Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-1302

47
FAUCET Score

CVE-2025-1302 is a critical Remote Code Execution (RCE) vulnerability affecting jsonpath-plus versions prior to 10.3.0, stemming from insufficient input sanitization and an incomplete fix for CVE-2024-21534. An attacker can execute arbitrary code by exploiting the unsafe default 'eval=safe' mode. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 100/100 indicate a significant threat. Exploit intelligence shows a Nuclei template exists, and community discussion is high, suggesting active interest in this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
N/AJsonpath-Plus
>= 0, < 10.3.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

8.9HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
10.22%
Probability of exploitation in next 30 days
EPSS Percentile
95.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Nuclei: CVE-2025-1302 · Jul 26, 2025
This CVE's current EPSS score of 0.1022 is in the 91st percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: jsonpath-plusFixed in: 10.3.0

Vendor Advisories (2)

npmGHSA-hw8r-x6gr-5gjphigh

JSONPath Plus allows Remote Code Execution

Feb 15, 2025
redhatCVE-2025-1302Low

jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization

Feb 15, 2025

References

gist.github.com / nickcopi/11ba3cb4fdee6f89e02e6afae8db6456
github.com / JSONPath-Plus/JSONPath/blob/8e4acf8aff5f446aa66323e12394ac5615c3b260/src/Safe-Script.js%23L127
github.com / JSONPath-Plus/JSONPath/commit/30942896d27cb8a806b965a5ca9ef9f686be24ee
security.snyk.io / vuln/SNYK-JS-JSONPATHPLUS-8719585