CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-61140

Critical · CVSS 9.8

jsonpath (dchester/jsonpath) — Prototype Pollution

CVSS
9.8
nvd
EPSS
0.42%
34th pct
KEV
No
Class
other
CWE-1321, CWE-502

Description

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

Search profile — drives PoC discovery

Symbols valuelib/index.js__proto__constructorprototype
Keywords CVE-2025-61140jsonpath prototype pollutiondchester jsonpathjsonpath 1.1.1 value functionCWE-1321CWE-502
Versions: 1.1.1

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z