chore(aselo-webchat-react-app): remediate GHSA-87r5-mp6g-5w5j by overriding jsonpath to 1.3.0 - #4568
Merged
stephenhand merged 3 commits intoJul 29, 2026
Conversation
Co-authored-by: stephenhand <1694716+stephenhand@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Fix jsonpath arbitrary code injection vulnerability
chore(aselo-webchat-react-app): remediate GHSA-87r5-mp6g-5w5j by overriding jsonpath to 1.3.0
Jul 29, 2026
Contributor
There was a problem hiding this comment.
🟢 Ready to approve
The PR is a straightforward dependency override + lockfile regeneration to a known patched version, with no functional source changes and no issues found in the updated resolution.
This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.
Pull request overview
Remediates Dependabot-reported vulnerability GHSA-87r5-mp6g-5w5j / CVE-2026-1615 in aselo-webchat-react-app by forcing the transitive jsonpath dependency to resolve to the lowest patched version (1.3.0) and updating the lockfile accordingly.
Changes:
- Added an npm
overridesentry inaselo-webchat-react-app/package.jsonto pinjsonpathto1.3.0. - Regenerated
aselo-webchat-react-app/package-lock.jsonsonode_modules/jsonpathresolves to1.3.0(and its updated dependency set, e.g.,static-eval@2.1.1,underscore@1.13.6).
File summaries
| File | Description |
|---|---|
| aselo-webchat-react-app/package.json | Adds an npm override to force jsonpath@1.3.0. |
| aselo-webchat-react-app/package-lock.json | Updates the resolved dependency graph to reflect jsonpath@1.3.0 and related transitive updates. |
Review details
Files not reviewed (1)
- aselo-webchat-react-app/package-lock.json: Generated file
- Files reviewed: 1/2 changed files
- Comments generated: 0
- Review effort level: Low
We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Dependabot flagged
jsonpath@1.1.1(GHSA-87r5-mp6g-5w5j / CVE-2026-1615) inaselo-webchat-react-app/package-lock.jsonfor unsafe evaluation. This updates to the lowest patched version (1.3.0) and documents reachability.Dependency remediation
aselo-webchat-react-app/package.json:"overrides": { "jsonpath": "1.3.0" }aselo-webchat-react-app/package-lock.jsonvia npm tooling so transitive pathreact-scripts -> bfj -> jsonpathresolves to1.3.0.Reachability Assessment
jsonpath.query,nodes,paths,value,parent,apply.aselo-webchat-react-appsource.Code change snippet
{ "overrides": { "handlebars": "4.7.9", "rollup": "2.80.0", "flatted": "3.4.2", "systeminformation": "5.31.0", "jsonpath": "1.3.0" } }Checklist
Other Related Issues
None
Verification steps
/home/runner/work/flex-plugins/flex-plugins/aselo-webchat-react-app, run:npm ls jsonpathjsonpath@1.3.0underreact-scripts -> bfj.jsonpathAPIs.AFTER YOU MERGE
You are responsible for ensuring the above steps are completed. If you move a ticket into QA without advising what version to test, the QA team will assume the latest tag has the changes. If it does not, the following confusion is on you! :-P
Original prompt
This section details the Dependabot vulnerability alert you should resolve
<alert_title>jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions</alert_title>
<alert_description>### Impact
Arbitrary Code Injection (Remote Code Execution & XSS):
A critical security vulnerability affects all versions of the
jsonpathpackage. The library relies on thestatic-evalmodule to evaluate JSON Path expressions but fails to properly sanitize or sandbox the input.This allows an attacker to inject arbitrary JavaScript code into the JSON Path expression. When the library evaluates this expression, the malicious code is executed.
Affected Methods:
The vulnerability triggers when untrusted data is passed to any method that evaluates a path, including:
jsonpath.queryjsonpath.nodesjsonpath.pathsjsonpath.valuejsonpath.parentjsonpath.applyPatches
No Patch Available:
Currently, all versions of
jsonpathare vulnerable. There is no known patched version of this package that resolves the issue while retaining the current architecture.Recommendation:
Developers are strongly advised to migrate to a secure alternative (such as
jsonpath-plusor similar libraries that do not useeval/static-eval) or strictly validate all JSON Path inputs against a known allowlist.Workarounds
jsonpathfunctions.(), script expressionsscript:, or function calls).Resources
high
https://nvd.nist.gov/vuln/detail/CVE-2026-1615 https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15141219 https://security.snyk.io/vuln/SNYK-JS-JSONPATH-13645034 https://github.com/dchester/jsonpath/blob/c1dd8ec74034fb0375233abb5fdbec51ac317b4b/lib/handlers.js#L243 https://github.com/dchester/jsonpath/pull/197 https://github.com/dchester/jsonpath/commit/491e2e01de2ff13f7d95e87eb2be726edbf4225f https://github.com/dchester/jsonpath/commit/b61111f07ac1a8d0f3133b5fc51438ecb76a6c39 https://github.com/advisories/GHSA-87r5-mp6g-5w5jGHSA-87r5-mp6g-5w5j, CVE-2026-1615
jsonpath
npm
<vulnerable_versions>1.1.1</vulnerable_versions>
<patched_version>1.3.0</patched_version>
<manifest_path>aselo-webchat-react-app/package-lock.json</manifest_path>
<task_instructions>Resolve this alert by updating the affected package to a non-vulnerable version. Prefer the lowest non-vulnerable version (see the patched_version field above) over the latest to minimize breaking changes. Include a Reachability Assessment section in the PR description. Review the alert_description field to understand which APIs, features, or configurations are affected, then search the codebase for usage of those specific items. If the vulnerable code path is reachable, explain how (which files, APIs, or call sites use the affected functionality) and note that the codebase is actively exposed to this vulnerability. If the vulnerable code path is not reachable, explain why (e.g. the affected API is never called, the vulnerable configuration is not used) and note that the update is primarily to satisfy vulnerability scanners rather than to address an active risk. If the advisory is too vague to determine reachability (e.g. 'improper input validation' with no specific API named), state that reachability could not be determined and explain why. Include a confidence level in the reachability assessment (e.g. high confidence if the advisory names a specific API and you confirmed it is or is not called, low confidence if the usage is indirect and hard to trace). If no patched version is available, check the alert_description field for a Workarounds section — the advisory may describe configuration changes or usage patterns that mitigate the vulnerability without a version update. If a workaround is available, apply it and leave a code comment referencing the advisory identifie...