CVE-2025-61140
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-61140, https://github.com/dchester/jsonpath/issues/181, https://github.com/dchester/jsonpath/issues/194, https://github.com/dchester/jsonpath/pull/195, https://github.com/dchester/jsonpath/commit/9631412641b7095f86840a7a45b5b3afc68b0fcb, https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d, https://github.com/dchester/jsonpath
