CVE-2025-61140

EUVD-2025-206486
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
Prototype Pollution
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 35.18%
Affected Products (NVD)
VendorProductVersion
dchesterjsonpath
1.1.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.1
1770282458 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5
1772214630 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1772552788 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.8
1774545605 ≤
𝑥
< *
ADP
Red HatRed Hat Developer Hub 1.9
1775140647 ≤
𝑥
< *
ADP
Red HatSelf-service automation portal 2.0
1770281704 ≤
𝑥
< *
ADP