Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1615

35
FAUCET Score

CVE-2026-1615 is a critical arbitrary code injection vulnerability affecting versions of the 'jsonpath' package prior to 1.2.0. It arises from the unsafe evaluation of user-supplied JSON Path expressions, which leverage the 'static-eval' module not designed for untrusted input. This flaw allows an unauthenticated attacker to execute arbitrary JavaScript code, leading to Remote Code Execution in Node.js or Cross-site Scripting in browsers, impacting all methods that evaluate JSON Paths. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, resulting in complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
N/AJsonpath
>= 0, < 1.3.0CNA affected
N/AOrg.Webjars.Npm:Jsonpath
>= 0, < *CNA affected

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.05%
Probability of exploitation in next 30 days
EPSS Percentile
60.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0105 is in the 46th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

npmpatch availablevia ghsa
Product: jsonpathFixed in: 1.3.0
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-26/lightspeed-rhel9
redhatno patchvia redhat_api
Product: Red Hat Developer HubFixed in: rhdh/rhdh-hub-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-cuda-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/disk-image-cuda-rhel9
redhatno patchvia redhat_api
Product: Self-service automation portal 2Fixed in: ansible-automation-platform/automation-portal
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-24/lightspeed-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/lightspeed-rhel8
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-console-plugin-rhel9
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-on-clouds/aoc-azure-aap-installer-rhel9
redhatend of lifevia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-api-rhel8
redhatend of lifevia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-db-migration-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.hawt-hawtio-online
redhatend of lifevia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: mtv-candidate/mtv-console-plugin-rhel9

Vendor Advisories (2)

npmGHSA-87r5-mp6g-5w5jhigh

jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions

Feb 9, 2026
redhatCVE-2026-1615Important

jsonpath: jsonpath: Arbitrary Code Execution via unsafe JSON Path expression evaluation

Feb 9, 2026

References

access.redhat.com / errata/RHSA-2026:6308
access.redhat.com / errata/RHSA-2026:6309
access.redhat.com / errata/RHSA-2026:6802
access.redhat.com / security/cve/CVE-2026-1615
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-1615.json
github.com / dchester/jsonpath/blob/c1dd8ec74034fb0375233abb5fdbec51ac317b4b/lib/handlers.js%23L243
github.com / dchester/jsonpath/commit/b61111f07ac1a8d0f3133b5fc51438ecb76a6c39
security.snyk.io / vuln/SNYK-JAVA-ORGWEBJARSNPM-15141219
security.snyk.io / vuln/SNYK-JS-JSONPATH-13645034