CVE-2020-7766: JSON-Ptr Project JSON-Ptr
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set, leading to a prototype pollution.
Affected products
- JSON-Ptr Project JSON-Ptr: before 2.0.0 (fixed in 2.0.0)
Published 2020-11-10. Last modified 2026-06-17.