CVE-2025-1302 is a remote code execution vulnerability in jsonpath-plus versions before 10.3.0. Improper input sanitization in the unsafe default use of eval='safe' mode allows attacker-controlled input to execute arbitrary code on the system. The issue is an incomplete fix for CVE-2024-21534.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
eval='safe' mode, and strictly allowlist supported JSONPath syntax. Run the consuming Node.js service with least privilege and restrict its access to sensitive resources as defense in depth.Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a self-contained research PoC demonstrating jsonpath-plus RCE (CVE-2025-1302) using jsonpath-plus@10.2.0 in a minimal Express server. Structure/purpose: - server.js: Main vulnerable web app. Exposes GET /query that reads req.query.path and passes it directly to JSONPath({path: userPath, json: dummyData, wrap:true}). This enables JSONPath filter expression injection leading to arbitrary JS execution in the Node process. - test_jp.js: Minimal local reproduction snippet calling JSONPath with a constructor/Function-based payload. - Dockerfile + docker-compose.yml: Containerized environment (Node 18-alpine) exposing container port 3000 and mapping host 3002->3000 for easy testing. - README.md and TESTING.md: Detailed write-up and step-by-step reproduction, including the key bypass technique using array notation [["constructor"]] to evade BLOCKED_PROTO_PROPERTIES checks and reach the Function constructor. Exploit capabilities: - Remote Code Execution via network: attacker supplies a crafted JSONPath in the `path` query parameter to /query. - Sandbox/blacklist bypass: uses array-notation property access to bypass blocked proto property checks, then executes arbitrary code via Function constructor. - Command execution and output exfiltration: demonstrated with child_process.execSync('id') and returning output by throwing an Error that is reflected in the HTTP 500 response. Overall, this is a PoC/simulation environment rather than a weaponized exploit: it provides a vulnerable service and example payloads, but no automation for scanning or mass exploitation.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-1302, a remote code execution (RCE) vulnerability in the 'jsonpath-plus' Node.js library (version 10.2.0). The main exploit script, 'poc.py', is a Python 3 tool that sends malicious JSONPath payloads to a specified HTTP endpoint (e.g., /query) on a target server running the vulnerable library. The script supports both POST and GET methods, with fallback logic, and can use either a built-in reverse shell payload or custom payloads from a file. The exploit attempts to execute arbitrary commands on the server by injecting a JSONPath expression that leverages Node.js's 'child_process' module to spawn a bash reverse shell, connecting back to the attacker's machine. The script includes features for verbose debugging, progress indication, and optional logging of results. The repository also contains a 'package.json' file describing a sample vulnerable server setup (not included in the files provided), a README with detailed usage instructions, and an MIT license. The exploit is intended for use in controlled environments for security testing and research.
This repository provides a proof-of-concept (PoC) exploit for CVE-2025-1302, a remote code execution (RCE) vulnerability in the 'jsonpath-plus' Node.js package (versions before 10.3.0). The vulnerability arises from improper input sanitization, allowing attackers to inject malicious JSONPath expressions that are evaluated unsafely, leading to arbitrary code execution. The main exploit script, 'CVE-2025-1302.py', is a Python tool that sends a specially crafted JSONPath payload to a vulnerable endpoint (typically '/query' on the target server). This payload leverages Node.js's 'child_process' module to execute a bash reverse shell, connecting back to the attacker's specified IP and port. The exploit requires the attacker to set up a listener (e.g., with netcat) to receive the shell. The repository also includes a Dockerfile and a Node.js application ('server.js') that simulates a vulnerable environment using 'jsonpath-plus' 10.2.0. The web interface (HTML/CSS/JS in 'public/') is for demonstration and testing. The exploit is not a detection script but a functional RCE PoC, and the README provides clear setup and usage instructions. Key endpoints include the '/query' POST route (vulnerable to injection) and the attacker's TCP listener for the reverse shell. The exploit demonstrates the risk of unsanitized user input in JSONPath evaluation and is intended for educational and testing purposes.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.