The Lab · 2026-04-30 16:54:12 · GitHub Issues
A P0 security vulnerability has been identified in SharpSite's plugin and configuration system, exposing at least four code locations to Remote Code Execution (RCE) through insecure deserialization. The flaw centers on Newtonsoft.Json's `TypeNameHandling.Auto` setting, a well-documented attack vector that allows advers...
The Lab · 2026-05-14 07:48:23 · GitHub Issues
A development fork of the popular eShopOnContainers e-commerce reference architecture has been flagged for including a known-severity vulnerability in its test suite dependencies. WhiteSource security scanning detected the presence of Newtonsoft.Json version 12.0.2—a package with a documented CVSS score of 7.5—packaged...
The Lab · 2026-05-14 07:48:27 · GitHub Issues
A security vulnerability has been identified in the Newtonsoft.Json 10.0.3 dependency bundled within the Microsoft.AspNetCore.HealthChecks 1.0.0 library, affecting the eShopOnContainers project's Webhooks.API component. The flaw carries a CVSS score of 7.5, placing it in the medium-high severity range. The vulnerabilit...