CVE-2026-1615 is being flagged (no pun) on flagsmith beacuse of the jsonpath dependency.
This doesn't seem likely to be fixed soon in jsonpath: dchester/jsonpath#196
Not sure of the best solution because i don't know how hard it would be to remove that dependency.