VYPR

JSON Schema Ref Parser

by Apidevtools

Source repositories

CVEs (2)

  • CVE-2024-29651HigMay 20, 2024
    risk 0.46cvss 8.1epss 0.01

    A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions.

  • CVE-2026-15195MedJul 9, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Pointer.set in the library lib/pointer.ts. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack can…