Apparently there is a critical vulnerability with jsonpath-plus < 10.0.7  https://www.npmjs.com/package/jsonpath-plus