CVE-2026-1615 is a critical arbitrary code injection vulnerability affecting versions of the 'jsonpath' package prior to 1.2.0. It arises from the unsafe evaluation of user-supplied JSON Path expressions, which leverage the 'static-eval' module not designed for untrusted input. This flaw allows an unauthenticated attacker to execute arbitrary JavaScript code, leading to Remote Code Execution in Node.js or Cross-site Scripting in browsers, impacting all methods that evaluate JSON Paths. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, resulting in complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Jsonpath | >= 0, < 1.3.0CNA affected | |
| N/A | Org.Webjars.Npm:Jsonpath | >= 0, < *CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.