CVE-2025-1302 is a critical Remote Code Execution (RCE) vulnerability affecting jsonpath-plus versions prior to 10.3.0, stemming from insufficient input sanitization and an incomplete fix for CVE-2024-21534. An attacker can execute arbitrary code by exploiting the unsafe default 'eval=safe' mode. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 100/100 indicate a significant threat. Exploit intelligence shows a Nuclei template exists, and community discussion is high, suggesting active interest in this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Jsonpath-Plus | >= 0, < 10.3.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.