
🔴 CVE-2026-33228 - Critical flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled string values from the parsed JSON as direct array index keys, witho... https://www.thehackerwire.com/vulnerability/CVE-2026-33228/ https://t.co/EitPKqKtfF
Post summary
The post alerts to a critical flaw in flatted's parse() function that lets attacker-controlled strings become array indices, but it provides no exploit evidence or patch guidance.

