The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
References
| Link | Resource |
|---|---|
| https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d | Third Party Advisory |
| https://github.com/dchester/jsonpath | Product |
Configurations
History
No history.
Information
Published : 2026-01-28 16:16
Updated : 2026-02-09 19:06
NVD link : CVE-2025-61140
Mitre link : CVE-2025-61140
CVE.ORG link : CVE-2025-61140
JSON object : View
Products Affected
dchester
- jsonpath
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
