JSONPath-plus.CVE-2025-1302.Remote.Code.Execution

description-logoDescription

This indicates a possible attack against a Remote Code Execution vulnerability in JSONPath-plus package.
The vulnerability is due to lack of input validation when handling requests. A remote attacker can exploit this vulnerability by sending maliciously crafted requests to the vulnerable server. Successful exploitation could result in arbitrary code execution in the security context of the application.

affected-products-logoAffected Products

jsonpath-plus versions before 10.3.0

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://github.com/JSONPath-Plus/JSONPath/commit/30942896d27cb8a806b965a5ca9ef9f686be24ee

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2025-12-11 35.133
Modified
Sig Added
2025-03-31 31.979
Modified
Default_action:pass:drop
2025-03-19 31.973
New