CVE-2020-7712High· 7.2▾ TwilightThis affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.1%
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
json < 10.0.0commerce_guided_search = 11.3.2financial_services_crime_and_compliance_management_studio = 8.0.8.2.0financial_services_crime_and_compliance_management_studio = 8.0.8.3.0financial_services_regulatory_reporting_with_agilereporter = 8.0.9.6.3timesten_in-memory_database < 21.1.1.1.0Upgrade past the affected range:
json 10.0.0timesten_in-memory_database 21.1.1.1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-21345Medium· 5.8XStream is a Java library to serialize objects to XML and back again
CVE-2020-26217High· 8.0XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream
CVE-2026-71847LowRuby JSON is a JSON implementation for Ruby
CVE-2026-54696Low· 3.7Ruby json: JSON generator heap buffer overflow when streaming to an IO
CVE-2026-33210Critical· 9.1Ruby JSON is a JSON implementation for Ruby
CVE-2021-32751High· 7.5Gradle is a build tool with a focus on build automation