Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2025-61140
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.004
EPSS Ranking
32.7%
CVSS Severity
CVSS v3 Score
9.8
References
https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d
https://github.com/dchester/jsonpath
https://access.redhat.com/errata/RHSA-2026:2180
https://access.redhat.com/errata/RHSA-2026:2181
https://access.redhat.com/errata/RHSA-2026:3960
https://access.redhat.com/errata/RHSA-2026:3962
https://access.redhat.com/errata/RHSA-2026:6174
https://access.redhat.com/errata/RHSA-2026:6802
https://access.redhat.com/security/cve/CVE-2025-61140
https://bugzilla.redhat.com/show_bug.cgi?id=2433946
https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61140.json
Products affected by CVE-2025-61140
Dchester
»
Jsonpath
»
Version:
1.1.1
cpe:2.3:a:dchester:jsonpath:1.1.1
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved