Skip to content

jsonpath has high severity CVE-2026-1615 and no fix #246

@sam-super

Description

@sam-super

CVE-2026-1615 is being flagged (no pun) on flagsmith beacuse of the jsonpath dependency.

This doesn't seem likely to be fixed soon in jsonpath: dchester/jsonpath#196

Not sure of the best solution because i don't know how hard it would be to remove that dependency.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions