3 ms·
I feel I must still be misunderstanding something. OWASP has pages of resources which talk about the lack of safety of JSON: https://owasp.org/search/?searchSt
by bshacklett 3y ago
I feel I must still be misunderstanding something. OWASP has pages of resources which talk about the lack of safety of JSON:
https://owasp.org/search/?searchString=json https://owasp.org/search/?searchString=json
Perhaps yaml and xml have _more_ ways to inject behavior into an application, but I would still not consider JSON safe in any way. Why would JSON.parse() even exist if `require()` and `eval()` were safe to use?