jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization
Published Oct 11, 2024
9.3
CRITICALCVSS 4.0
EPSS 9.02%
Description
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix it in versions [10.0.0-10.1.0](https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0) but it could still be exploited using [different payloads](https://github.com/JSONPath-Plus/JSONPath/issues/226).
Affected products
- Vendor n/a Product Jsonpath-Plus Defaultn/a
- Version 0StatusaffectedConstraints<*
- Version
- Vendor n/a Product Org.webjars.npm:jsonpath-Plus Defaultn/a
- Version 0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Jsonpath-Plus | n/a |
| ||||||
| n/a | Org.webjars.npm:jsonpath-Plus | n/a |
|
No data.
-
- Version 0StatusaffectedConstraints<10.0.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Jsonpath-Plus | Jsonpath | n/a |
|
Red Hat Developer Hub 1.6
rhdh/rhdh-hub-rhel9:1.6.0-1745956724
Fixed · RHSA-2025:7626
Red Hat OpenShift Dev Spaces 3 Containers
devspaces/code-rhel8:3.17-19
Fixed · RHSA-2024:10236
Red Hat OpenShift Dev Spaces 3 Containers
devspaces/dashboard-rhel8:3.17-25
Fixed · RHSA-2024:10236
Red Hat Developer Hub
rhdh/rhdh-rhel9-operator
Not affected
Red Hat OpenShift AI (RHOAI)
odh-dashboard-container
Fix deferred
Red Hat OpenShift AI (RHOAI)
odh-operator-container
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-dashboard-rhel8
Fix deferred
Red Hat OpenShift Data Science (RHODS)
rhods/odh-operator-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-rhel8-operator
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Hub 1.6 | rhdh/rhdh-hub-rhel9:1.6.0-1745956724 | Fixed | RHSA-2025:7626 |
| Red Hat OpenShift Dev Spaces 3 Containers | devspaces/code-rhel8:3.17-19 | Fixed | RHSA-2024:10236 |
| Red Hat OpenShift Dev Spaces 3 Containers | devspaces/dashboard-rhel8:3.17-25 | Fixed | RHSA-2024:10236 |
| Red Hat Developer Hub | rhdh/rhdh-rhel9-operator | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-dashboard-container | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-operator-container | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-dashboard-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-operator-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-rhel8-operator | Not affected | n/a |
org.webjars.npm:jsonpath-plus
Maven
Introduced 0 Fixed not fixedjsonpath-plus
npm
Introduced 0 Fixed 10.2.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Maven | org.webjars.npm:jsonpath-plus | 0 | not fixed |
| npm | jsonpath-plus | 0 | 10.2.0 |
Remediation
Red Hat statement
Red Hat's initial impact rating of critical has been downgraded to low. While the vulnerable code is technically still present within Red Hat products, there are no code paths in affected products which allow exploitation. As such, the impact to Red Hat products is low. Each of the products listed have multiple components where a fixed build could occur. This distinction does not matter for users as only one build needs fixed for the product. Additionally, in Red Hat OpenShift AI, jsonpath-plus is a dependency of a direct dependency and is never loaded, as the direct dependency's feature that requires jsonpath-plus is not used.
Red Hat mitigation
Red Hat Product Security recommends updating the vulnerable software to the latest version.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Oct 11, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 9.02% (0.09017) | 95.13th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.08% (0.09076) | 94.62th | v5 (v2026.06.15) |
| Nov 21, 2025 | 91.83% (0.91835) | 99.67th | v4 (v2025.03.14) |
| Nov 18, 2025 | 81.77% (0.81768) | 99.27th | v4 (v2025.03.14) |
| Nov 5, 2025 | 87.36% (0.87358) | 99.41th | v4 (v2025.03.14) |
| Aug 7, 2025 | 40.62% (0.40615) | 97.24th | v4 (v2025.03.14) |
| Jul 16, 2025 | 39.43% (0.39430) | 97.14th | v4 (v2025.03.14) |
| Jun 27, 2025 | 45.98% (0.45979) | 97.48th | v4 (v2025.03.14) |
| May 18, 2025 | 44.94% (0.44944) | 97.42th | v4 (v2025.03.14) |
| May 17, 2025 | 40.57% (0.40574) | 97.17th | v4 (v2025.03.14) |
| May 15, 2025 | 38.16% (0.38159) | 97.01th | v4 (v2025.03.14) |
| Apr 15, 2025 | 42.50% (0.42497) | 97.23th | v4 (v2025.03.14) |
| Mar 17, 2025 | 68.02% (0.68022) | 98.47th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00045) | 17.74th | v3 (v2023.03.01) |
| Oct 12, 2024 | 0.04% (0.00043) | 9.70th | v3 (v2023.03.01) |
References (14)
- https://access.redhat.com/security/cve/CVE-2024-21534 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2317968 Issue Tracking
- https://github.com/JSONPath-Plus/JSONPath/commit/6b2f1b4c234292c75912b790bf7e2d7339d4ccd3
- https://github.com/JSONPath-Plus/JSONPath/commit/73ad72e5ee788d8287dea6e8283a3f16f63c9eb8
- https://github.com/JSONPath-Plus/JSONPath/commit/b70aa713553caf838a63bac923195a5bc541fd72
- https://github.com/JSONPath-Plus/JSONPath/compare/v9.0.0...v10.1.0
- https://github.com/JSONPath-Plus/JSONPath/issues/226
- https://github.com/JSONPath-Plus/JSONPath/issues/226#issuecomment-2424230316
- https://github.com/JSONPath-Plus/JSONPath/pull/233
- https://github.com/advisories/GHSA-pppg-cpfq-h7wr Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-21534
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8185019
- https://security.snyk.io/vuln/SNYK-JS-JSONPATHPLUS-7945884
- https://www.cve.org/CVERecord?id=CVE-2024-21534
Change history (0)
No recorded changes yet.