Skip to content

Commit a54beff

Browse files
committed
fix: allow bare @ in any position (e.g., $[?(@)], $[?(!@)],
`$[?(@?1:0)]`) and avoid rewriting `@` inside quoted string literals
1 parent 935c782 commit a54beff

13 files changed

Lines changed: 69 additions & 11 deletions

‎CHANGES.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,11 @@
11
# CHANGES for jsonpath-plus
22

3+
## 11.0.2
4+
5+
- fix: allow bare `@` in any position (e.g., `$[?(@>1)]`, `$[?(@)]`,
6+
`$[?(!@)]`) and stop rewriting `@` inside quoted string literals
7+
(@spokodev)
8+
39
## 11.0.1
410

511
- fix(security) nested filter bypass exploit (@andrewmacheret)

‎badges/tests-badge.svg‎

Lines changed: 1 addition & 1 deletion
Loading

‎dist/index-browser-esm.js‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2369,7 +2369,10 @@ class JSONPathClass {
23692369
}
23702370
const scriptCacheKey = this.currEval + 'Script:' + code;
23712371
if (!scriptCache.has(scriptCacheKey)) {
2372-
let script = code.replaceAll('@parentProperty', '_$_parentProperty').replaceAll('@parent', '_$_parent').replaceAll('@property', '_$_property').replaceAll('@root', '_$_root').replaceAll(/@([.\s\)\[])/gv, '_$_v$1');
2372+
let script = code.replaceAll('@parentProperty', '_$_parentProperty').replaceAll('@parent', '_$_parent').replaceAll('@property', '_$_property').replaceAll('@root', '_$_root')
2373+
// Replace a bare `@` (not followed by an identifier
2374+
// character) while leaving quoted string literals intact
2375+
.replaceAll(/('(?:\\.|[^'\\])*'|"(?:\\.|[^"\\])*")|@(?![\w$])/gv, (_, str) => str ?? '_$_v');
23732376
if (containsPath) {
23742377
script = script.replaceAll('@path', '_$_path');
23752378
}

‎dist/index-browser-esm.min.js‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎dist/index-browser-esm.min.js.map‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎dist/index-browser-umd.cjs‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2375,7 +2375,10 @@
23752375
}
23762376
const scriptCacheKey = this.currEval + 'Script:' + code;
23772377
if (!scriptCache.has(scriptCacheKey)) {
2378-
let script = code.replaceAll('@parentProperty', '_$_parentProperty').replaceAll('@parent', '_$_parent').replaceAll('@property', '_$_property').replaceAll('@root', '_$_root').replaceAll(/@([.\s\)\[])/gv, '_$_v$1');
2378+
let script = code.replaceAll('@parentProperty', '_$_parentProperty').replaceAll('@parent', '_$_parent').replaceAll('@property', '_$_property').replaceAll('@root', '_$_root')
2379+
// Replace a bare `@` (not followed by an identifier
2380+
// character) while leaving quoted string literals intact
2381+
.replaceAll(/('(?:\\.|[^'\\])*'|"(?:\\.|[^"\\])*")|@(?![\w$])/gv, (_, str) => str ?? '_$_v');
23792382
if (containsPath) {
23802383
script = script.replaceAll('@path', '_$_path');
23812384
}

‎dist/index-browser-umd.min.cjs‎

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

‎dist/index-browser-umd.min.cjs.map‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎dist/index-node-cjs.cjs‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2373,7 +2373,10 @@ class JSONPathClass {
23732373
}
23742374
const scriptCacheKey = this.currEval + 'Script:' + code;
23752375
if (!scriptCache.has(scriptCacheKey)) {
2376-
let script = code.replaceAll('@parentProperty', '_$_parentProperty').replaceAll('@parent', '_$_parent').replaceAll('@property', '_$_property').replaceAll('@root', '_$_root').replaceAll(/@([.\s\)\[])/gv, '_$_v$1');
2376+
let script = code.replaceAll('@parentProperty', '_$_parentProperty').replaceAll('@parent', '_$_parent').replaceAll('@property', '_$_property').replaceAll('@root', '_$_root')
2377+
// Replace a bare `@` (not followed by an identifier
2378+
// character) while leaving quoted string literals intact
2379+
.replaceAll(/('(?:\\.|[^'\\])*'|"(?:\\.|[^"\\])*")|@(?![\w$])/gv, (_, str) => str ?? '_$_v');
23772380
if (containsPath) {
23782381
script = script.replaceAll('@path', '_$_path');
23792382
}

‎dist/index-node-esm.js‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2371,7 +2371,10 @@ class JSONPathClass {
23712371
}
23722372
const scriptCacheKey = this.currEval + 'Script:' + code;
23732373
if (!scriptCache.has(scriptCacheKey)) {
2374-
let script = code.replaceAll('@parentProperty', '_$_parentProperty').replaceAll('@parent', '_$_parent').replaceAll('@property', '_$_property').replaceAll('@root', '_$_root').replaceAll(/@([.\s\)\[])/gv, '_$_v$1');
2374+
let script = code.replaceAll('@parentProperty', '_$_parentProperty').replaceAll('@parent', '_$_parent').replaceAll('@property', '_$_property').replaceAll('@root', '_$_root')
2375+
// Replace a bare `@` (not followed by an identifier
2376+
// character) while leaving quoted string literals intact
2377+
.replaceAll(/('(?:\\.|[^'\\])*'|"(?:\\.|[^"\\])*")|@(?![\w$])/gv, (_, str) => str ?? '_$_v');
23752378
if (containsPath) {
23762379
script = script.replaceAll('@path', '_$_path');
23772380
}

0 commit comments

Comments
 (0)