The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
References
| Link | Resource |
|---|---|
| https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d | Third Party Advisory |
| https://github.com/dchester/jsonpath | Product |
Configurations
History
09 Feb 2026, 19:06
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:dchester:jsonpath:1.1.1:*:*:*:*:*:*:* | |
| First Time |
Dchester jsonpath
Dchester |
|
| References | () https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d - Third Party Advisory | |
| References | () https://github.com/dchester/jsonpath - Product |
29 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-1321 |
28 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-28 16:16
Updated : 2026-02-09 19:06
NVD link : CVE-2025-61140
Mitre link : CVE-2025-61140
CVE.ORG link : CVE-2025-61140
JSON object : View
Products Affected
dchester
- jsonpath
CWE
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
