WhisperX tag archive

#Newtonsoft.Json

This page collects WhisperX intelligence signals tagged #Newtonsoft.Json. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-30 16:54:12 · GitHub Issues

1. SharpSite Plugin System Exposed to Critical RCE via Insecure JSON Deserialization

A P0 security vulnerability has been identified in SharpSite's plugin and configuration system, exposing at least four code locations to Remote Code Execution (RCE) through insecure deserialization. The flaw centers on Newtonsoft.Json's `TypeNameHandling.Auto` setting, a well-documented attack vector that allows advers...

The Lab · 2026-05-14 07:48:23 · GitHub Issues

2. eShopOnContainers Fork Exposes Test Environment to CVE-2024-21907 via Vulnerable Newtonsoft.Json Dependency

A development fork of the popular eShopOnContainers e-commerce reference architecture has been flagged for including a known-severity vulnerability in its test suite dependencies. WhiteSource security scanning detected the presence of Newtonsoft.Json version 12.0.2—a package with a documented CVSS score of 7.5—packaged...

The Lab · 2026-05-14 07:48:27 · GitHub Issues

3. CVE-2024-21907: Newtonsoft.Json 10.0.3 Vulnerability Exposes eShopOnContainers Webhooks.API to Medium-High Risk

A security vulnerability has been identified in the Newtonsoft.Json 10.0.3 dependency bundled within the Microsoft.AspNetCore.HealthChecks 1.0.0 library, affecting the eShopOnContainers project's Webhooks.API component. The flaw carries a CVSS score of 7.5, placing it in the medium-high severity range. The vulnerabilit...