Vulnerability Description
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://gist.github.com/nickcopi/11ba3cb4fdee6f89e02e6afae8db6456
- https://github.com/JSONPath-Plus/JSONPath/blob/8e4acf8aff5f446aa66323e12394ac561
- https://github.com/JSONPath-Plus/JSONPath/commit/30942896d27cb8a806b965a5ca9ef9f
- https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-8719585
FAQ
What is CVE-2025-1302?
CVE-2025-1302 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploitin...
How severe is CVE-2025-1302?
CVE-2025-1302 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-1302?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.