Hi, The jsonpath-plus module contains a 9.3/10 vulnerability about remote code execution. CVE details : https://github.com/advisories/GHSA-pppg-cpfq-h7wr The module vulnerability seems fixed in 10.xx versions.