Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.2
CVE-2026-1615: jsonpath: Malicious Code Can Run on Your Server
CVE-2026-1615 · published 1 day ago
Summary
The jsonpath library has a security flaw that allows hackers to run malicious code on your server. This can happen if you use the library to evaluate user input and don't properly check what's being passed in. To stay safe, consider switching to a different library or carefully validating all user input.
What to do
- Update jsonpath to version 1.3.0.
- Update jsonpath to version 1.1.1-aikido.1.
- Update rootio @rootio/jsonpath to version 1.1.1-root.io.1.
- Update org.webjars.npm:jsonpath to version * or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | dchester | jsonpath | <= 1.2.1 |
| npm | – | jsonpath |
<= 1.2.1 Fix: upgrade to 1.3.0
|
| – | – | jsonpath | < 1.3.0 |
| – | – | org.webjars.npm:jsonpath | < * |
| Root:npm | – | jsonpath |
< 1.1.1-aikido.1 Fix: upgrade to 1.1.1-aikido.1
|
| Root:npm | rootio | @rootio/jsonpath |
< 1.1.1-root.io.1 Fix: upgrade to 1.1.1-root.io.1
|
Original advisory text
CVE-2026-1615 in jsonpath - Patched by Root
Root has patched CVE-2026-1615 in the jsonpath package for Root:npm. Multiple fixed versions available.
References
- https://github.com/dchester/jsonpath/blob/c1dd8ec74034fb0375233abb5fdbec51ac317b...
- https://github.com/dchester/jsonpath/commit/9631412641b7095f86840a7a45b5b3afc68b...
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15141219
- https://security.snyk.io/vuln/SNYK-JS-JSONPATH-13645034
- https://nvd.nist.gov/vuln/detail/CVE-2026-1615
- https://github.com/dchester/jsonpath/blob/c1dd8ec74034fb0375233abb5fdbec51ac317b...
- https://github.com/advisories/GHSA-87r5-mp6g-5w5j
- https://github.com/dchester/jsonpath/commit/b61111f07ac1a8d0f3133b5fc51438ecb76a...
- https://github.com/dchester/jsonpath/pull/197
- https://github.com/dchester/jsonpath/commit/491e2e01de2ff13f7d95e87eb2be726edbf4...
- https://access.redhat.com/errata/RHSA-2026:59155
- https://access.redhat.com/errata/RHSA-2026:6308
- https://access.redhat.com/errata/RHSA-2026:6309
- https://access.redhat.com/errata/RHSA-2026:6802
- https://access.redhat.com/security/cve/CVE-2026-1615
- https://bugzilla.redhat.com/show_bug.cgi?id=2437875
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1615.json
Severity
8.2
High
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS 1%
Type
CWE-94Code Injection
Timeline
Published2 Sep 2026
Updated2 Sep 2026
First seen6 Mar 2026
Monitor software like this
Free during beta