← Back to browse · API

CVE-2025-1302

Severity
CRITICAL
CVSS
9.3
EPSS
0.10224
Risk score
40.78
CISA KEV
No
PoC
No
Published
2025-02-15
Modified
2025-02-18
First seen
2026-08-07
Aliases
EUVD-2025-2104, GHSA-HW8R-X6GR-5GJP
Products
n/a:jsonpath-plus 0 <10.3.0
Sources
euvd EUVD-2025-2104

Description

Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).

References