Skip to content

chore(aselo-webchat-react-app): remediate GHSA-87r5-mp6g-5w5j by overriding jsonpath to 1.3.0 - #4568

Merged
stephenhand merged 3 commits into
masterfrom
copilot/fix-jsonpath-arbitrary-code-injection
Jul 29, 2026
Merged

stephenhand merged 3 commits into
masterfrom
copilot/fix-jsonpath-arbitrary-code-injection

Conversation

Copilot AI commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Description

Dependabot flagged jsonpath@1.1.1 (GHSA-87r5-mp6g-5w5j / CVE-2026-1615) in aselo-webchat-react-app/package-lock.json for unsafe evaluation. This updates to the lowest patched version (1.3.0) and documents reachability.

  • Dependency remediation

    • Added npm override in aselo-webchat-react-app/package.json:
      • "overrides": { "jsonpath": "1.3.0" }
    • Regenerated aselo-webchat-react-app/package-lock.json via npm tooling so transitive path react-scripts -> bfj -> jsonpath resolves to 1.3.0.
  • Reachability Assessment

    • Advisory-impacted APIs reviewed: jsonpath.query, nodes, paths, value, parent, apply.
    • No direct imports/call sites found in aselo-webchat-react-app source.
    • Current exposure is transitive only (tooling dependency path above), with no direct runtime call path from app code identified.
    • Confidence: High (specific API names provided by advisory + direct codebase search).
  • Code change snippet

{
  "overrides": {
    "handlebars": "4.7.9",
    "rollup": "2.80.0",
    "flatted": "3.4.2",
    "systeminformation": "5.31.0",
    "jsonpath": "1.3.0"
  }
}

Checklist

  • Corresponding issue has been opened
  • New tests added
  • Feature flags added
  • Strings are localized
  • Tested for chat contacts
  • Tested for call contacts

Other Related Issues

None

Verification steps

  • In /home/runner/work/flex-plugins/flex-plugins/aselo-webchat-react-app, run:
    • npm ls jsonpath
  • Confirm output resolves jsonpath@1.3.0 under react-scripts -> bfj.
  • Confirm no direct usage in app source for advisory-listed jsonpath APIs.

AFTER YOU MERGE

  1. Cut a release tag using the Github workflow. Wait for it to complete and notify in the #aselo-deploys Slack channel.
  2. Comment on the ticket with the release tag version AND any additional instructions required to configure an environment to test the changes.
  3. Only then move the ticket into the QA column in JIRA

You are responsible for ensuring the above steps are completed. If you move a ticket into QA without advising what version to test, the QA team will assume the latest tag has the changes. If it does not, the following confusion is on you! :-P

Original prompt

This section details the Dependabot vulnerability alert you should resolve

<alert_title>jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions</alert_title>
<alert_description>### Impact

Arbitrary Code Injection (Remote Code Execution & XSS):

A critical security vulnerability affects all versions of the jsonpath package. The library relies on the static-eval module to evaluate JSON Path expressions but fails to properly sanitize or sandbox the input.

This allows an attacker to inject arbitrary JavaScript code into the JSON Path expression. When the library evaluates this expression, the malicious code is executed.

  • Node.js Environments: This leads to Remote Code Execution (RCE), allowing an attacker to compromise the server.
  • Browser Environments: This leads to Cross-Site Scripting (XSS), allowing an attacker to hijack user sessions or exfiltrate data.

Affected Methods:

The vulnerability triggers when untrusted data is passed to any method that evaluates a path, including:

  • jsonpath.query
  • jsonpath.nodes
  • jsonpath.paths
  • jsonpath.value
  • jsonpath.parent
  • jsonpath.apply

Patches

No Patch Available:

Currently, all versions of jsonpath are vulnerable. There is no known patched version of this package that resolves the issue while retaining the current architecture.

Recommendation:

Developers are strongly advised to migrate to a secure alternative (such as jsonpath-plus or similar libraries that do not use eval/static-eval) or strictly validate all JSON Path inputs against a known allowlist.

Workarounds

  • Strict Input Validation: Ensure that no user-supplied data is ever passed directly to jsonpath functions.
  • Sanitization: If user input is unavoidable, implement a strict parser to reject any JSON Path expressions containing executable JavaScript syntax (e.g., parentheses (), script expressions script:, or function calls).

Resources

high
GHSA-87r5-mp6g-5w5j, CVE-2026-1615
jsonpath
npm
<vulnerable_versions>1.1.1</vulnerable_versions>
<patched_version>1.3.0</patched_version>
<manifest_path>aselo-webchat-react-app/package-lock.json</manifest_path>

https://nvd.nist.gov/vuln/detail/CVE-2026-1615 https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15141219 https://security.snyk.io/vuln/SNYK-JS-JSONPATH-13645034 https://github.com/dchester/jsonpath/blob/c1dd8ec74034fb0375233abb5fdbec51ac317b4b/lib/handlers.js#L243 https://github.com/dchester/jsonpath/pull/197 https://github.com/dchester/jsonpath/commit/491e2e01de2ff13f7d95e87eb2be726edbf4225f https://github.com/dchester/jsonpath/commit/b61111f07ac1a8d0f3133b5fc51438ecb76a6c39 https://github.com/advisories/GHSA-87r5-mp6g-5w5j

<task_instructions>Resolve this alert by updating the affected package to a non-vulnerable version. Prefer the lowest non-vulnerable version (see the patched_version field above) over the latest to minimize breaking changes. Include a Reachability Assessment section in the PR description. Review the alert_description field to understand which APIs, features, or configurations are affected, then search the codebase for usage of those specific items. If the vulnerable code path is reachable, explain how (which files, APIs, or call sites use the affected functionality) and note that the codebase is actively exposed to this vulnerability. If the vulnerable code path is not reachable, explain why (e.g. the affected API is never called, the vulnerable configuration is not used) and note that the update is primarily to satisfy vulnerability scanners rather than to address an active risk. If the advisory is too vague to determine reachability (e.g. 'improper input validation' with no specific API named), state that reachability could not be determined and explain why. Include a confidence level in the reachability assessment (e.g. high confidence if the advisory names a specific API and you confirmed it is or is not called, low confidence if the usage is indirect and hard to trace). If no patched version is available, check the alert_description field for a Workarounds section — the advisory may describe configuration changes or usage patterns that mitigate the vulnerability without a version update. If a workaround is available, apply it and leave a code comment referencing the advisory identifie...

Co-authored-by: stephenhand <1694716+stephenhand@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix jsonpath arbitrary code injection vulnerability chore(aselo-webchat-react-app): remediate GHSA-87r5-mp6g-5w5j by overriding jsonpath to 1.3.0 Jul 29, 2026
Copilot AI requested a review from stephenhand July 29, 2026 20:55
@stephenhand
stephenhand marked this pull request as ready for review July 29, 2026 21:33
Copilot AI review requested due to automatic review settings July 29, 2026 21:33
@stephenhand
stephenhand merged commit 2d60f38 into master Jul 29, 2026
24 checks passed
@stephenhand
stephenhand deleted the copilot/fix-jsonpath-arbitrary-code-injection branch July 29, 2026 21:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Ready to approve

The PR is a straightforward dependency override + lockfile regeneration to a known patched version, with no functional source changes and no issues found in the updated resolution.

This review doesn't count toward merge requirements. Sign up for the private preview to control whether Copilot approvals count.

Pull request overview

Remediates Dependabot-reported vulnerability GHSA-87r5-mp6g-5w5j / CVE-2026-1615 in aselo-webchat-react-app by forcing the transitive jsonpath dependency to resolve to the lowest patched version (1.3.0) and updating the lockfile accordingly.

Changes:

  • Added an npm overrides entry in aselo-webchat-react-app/package.json to pin jsonpath to 1.3.0.
  • Regenerated aselo-webchat-react-app/package-lock.json so node_modules/jsonpath resolves to 1.3.0 (and its updated dependency set, e.g., static-eval@2.1.1, underscore@1.13.6).
File summaries
File Description
aselo-webchat-react-app/package.json Adds an npm override to force jsonpath@1.3.0.
aselo-webchat-react-app/package-lock.json Updates the resolved dependency graph to reflect jsonpath@1.3.0 and related transitive updates.
Review details

Files not reviewed (1)

  • aselo-webchat-react-app/package-lock.json: Generated file
  • Files reviewed: 1/2 changed files
  • Comments generated: 0
  • Review effort level: Low

We're testing this review assessment. Please use 👍 or 👎 to tell us if it's correct.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants