peter bassill · operator
$ cve CVE-2025-1302 JSON

CVE-2025-1302

9.8
CRITICAL · CVSS 3.1 · EPSS 10.4% (pctl 96)

Patch early

EPSS 10.4% — above the 10% action threshold.

Description

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.4% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploitnone known
Published2025-02-15
Last modified2026-06-17

References

→ the Explorer  ·  watch your stack  ·  NVD