CVE-2025-61140: Dchester Jsonpath

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

Affected products

Published 2026-01-28. Last modified 2026-09-07.