CVE-2025-1302
92Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.3epss 10%
from disclosure to weapon10 days
Published on NVDFeb 15
1st PoC+10d
VulnCheck+277d
exploitation probability
10%top 5% of all CVEs
observed exploitation
yesVulnCheck
4 public exploit(s)
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode.
**Note:**
This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
n/a · jsonpath-pluspublic PoCs found — 4
githubgithub.com/EQSTLab/CVE-2025-1302★ 21githubgithub.com/abrewer251/CVE-2025-1302_jsonpath-plus_RCE★ 1vulncheckvulncheck.com/xdb/c666c58961e6unverifiedvulncheckvulncheck.com/xdb/a6624eafac6funverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://gist.github.com/nickcopi/11ba3cb4fdee6f89e02e6afae8db6456https://github.com/JSONPath-Plus/JSONPath/blob/8e4acf8aff5f446aa66323e12394ac5615c3b260/src/Safe-Script.js%23L127https://github.com/JSONPath-Plus/JSONPath/commit/30942896d27cb8a806b965a5ca9ef9f686be24eehttps://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-8719585