CVE-2025-1302: Code Injection
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode.
Note:
This is caused by an incomplete fix for [CVE-2024-21534](
Other sources
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode.
Note:
This is caused by an incomplete fix for CVE-2024-21534.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1302?
CVE-2025-1302 has a severity rating that indicates a critical risk of Remote Code Execution due to improper input sanitization.
How do I fix CVE-2025-1302?
To fix CVE-2025-1302, upgrade to jsonpath-plus version 10.3.0 or later, which addresses the vulnerability.
What types of systems are affected by CVE-2025-1302?
CVE-2025-1302 affects systems using versions of jsonpath-plus prior to 10.3.0.
What attack vectors are associated with CVE-2025-1302?
CVE-2025-1302 allows attackers to execute arbitrary code via Remote Code Execution due to unsafe default configurations.
Is there a workaround for CVE-2025-1302?
The recommended action for CVE-2025-1302 is upgrading the package, as no known workarounds are reliable.