CVE-2025-61140: JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js
(updated )
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
References
- gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d
- github.com/advisories/GHSA-6c59-mwgh-r2x6
- github.com/dchester/jsonpath
- github.com/dchester/jsonpath/commit/9631412641b7095f86840a7a45b5b3afc68b0fcb
- github.com/dchester/jsonpath/issues/181
- github.com/dchester/jsonpath/issues/194
- github.com/dchester/jsonpath/pull/195
- nvd.nist.gov/vuln/detail/CVE-2025-61140
Code Behaviors & Features
Detect and mitigate CVE-2025-61140 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →