CVE-2026-1615: Red Hat Migration Toolkit For Virtualization
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this vulnerability by supplying a malicious JSON Path expression that, when evaluated, executes arbitrary JavaScript code, leading to Remote Code Execution in Node.js environments or Cross-site Scripting (XSS) in browser contexts. This affects all methods that evaluate JSON Paths against objects, including .query, .nodes, .paths, .value, .parent, and .apply.
Affected products
- Red Hat Migration Toolkit For Virtualization
- Red Hat Openshift Pipelines
- Red Hat Red Hat Ansible Automation Platform 2
- Red Hat Red Hat Ansible Automation Platform 2.5: before 1774446874 (fixed in 1774446874)
- Red Hat Red Hat Ansible Automation Platform 2.6: before 1774363040 (fixed in 1774363040)
- Red Hat Red Hat Developer Hub 1.9: before 1775140647 (fixed in 1775140647)
- Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
- Red Hat Red Hat Fuse 7
- Red Hat Red Hat Openshift Ai Rhoai
- Red Hat Red Hat Quay 3
- Red Hat Self-Service Automation Portal 2
Published 2026-02-09. Last modified 2026-08-25.