Json5 is a JavaScript library that extends JSON syntax to support additional features such as comments and trailing commas, and has surfaced vulnerabilities centered on prototype pollution—a class of defect where untrusted input can modify object prototypes and corrupt application state across the runtime. The weakness reflects the dynamic nature of JavaScript object handling and the parser's interaction with language internals; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Json5 over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46175HIGH JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before a | Dec 24, 2022 | 8.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Json5.
Media articles that mention a CVE ID that affects a product developed by Json5 — matched by CVE ID, not by vendor name.