{"id":"CVE-2025-61140","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-61140","summary":"JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js","details":"The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.","published":"2026-01-28T18:30:47Z","modified":"2026-02-05T16:30:42.225658Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"jsonpath","fixedVersion":"1.2.0"}],"fix":{"url":"https://github.com/dchester/jsonpath/pull/195","label":"dchester/jsonpath#195"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61140"},{"type":"WEB","url":"https://github.com/dchester/jsonpath/issues/181"},{"type":"WEB","url":"https://github.com/dchester/jsonpath/issues/194"},{"type":"WEB","url":"https://github.com/dchester/jsonpath/pull/195"},{"type":"WEB","url":"https://github.com/dchester/jsonpath/commit/9631412641b7095f86840a7a45b5b3afc68b0fcb"},{"type":"WEB","url":"https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d"},{"type":"PACKAGE","url":"https://github.com/dchester/jsonpath"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-05T16:30:42.225658Z"}}