CVE-2025-61140
Critical · CVSS 9.8jsonpath (dchester/jsonpath) — Prototype Pollution
- CVSS
- 9.8
- nvd
- EPSS
- 0.42%
- 34th pct
- KEV
- No
- Class
- other
- CWE-1321, CWE-502
Description
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
Search profile — drives PoC discovery
Symbols valuelib/index.js__proto__constructorprototype
Keywords CVE-2025-61140jsonpath prototype pollutiondchester jsonpathjsonpath 1.1.1 value functionCWE-1321CWE-502
Versions: 1.1.1
References
- https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d
- https://github.com/dchester/jsonpath
- https://access.redhat.com/errata/RHSA-2026:2180
- https://access.redhat.com/errata/RHSA-2026:2181
- https://access.redhat.com/errata/RHSA-2026:3960
- https://access.redhat.com/errata/RHSA-2026:3962
- https://access.redhat.com/errata/RHSA-2026:6174
- https://access.redhat.com/errata/RHSA-2026:6802
- https://access.redhat.com/security/cve/CVE-2025-61140
- https://bugzilla.redhat.com/show_bug.cgi?id=2433946
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61140.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z