Query JavaScript objects with JSONPath expressions. Robust / safe JSONPath engine for Node.js.
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-1615 jsonpath is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 1.2.1. | 0.0.0 - 1.2.1 | Critical |
CVE-2025-61140 jsonpath is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 1.2.0. | 0.0.0 - 1.2.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
esprima Version 1.2.5 | — | — |
underscore Version 1.13.6 | — | — |
static-eval Version 2.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant