CVE-2025-61140: JSONPath vulnerable to Prototype Pollution due to insufficient input validation of object keys in lib/index.js
(updated )
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-61140 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →