CVE-2025-61140: Dchester Jsonpath
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
Affected products
- Dchester Jsonpath: version 1.1.1 only
Published 2026-01-28. Last modified 2026-09-07.