I am currently using Synk, and it has indicated a potential vulnerability for remote code execution. https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884