FlawAtlas
Search the atlas
CVE-2025-61140 Moderate

JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

Exploit probability 0.4%
Published January 28, 2026
Required by Not available
Last source change February 5, 2026

02 / AFFECTED SOFTWARE

Affected packages

npm jsonpath

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-6c59-mwgh-r2x6

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

View original source

05 / REFERENCES

Further evidence