A JS implementation of JSONPath with some additional operators
76%
Total Score
36
100
100
95
50
| Title | Versions | Severity |
|---|---|---|
CVE-2025-1302 jsonpath-plus is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 10.3.0. | 0.0.0 - 10.3.0 | Critical |
AIKIDO-2025-10096 jsonpath-plus is vulnerable to Remote Code Execution (RCE) in versions 10.2.0 - 10.2.0. | 10.2.0 - 10.2.0 | Critical |
AIKIDO-2024-10345 jsonpath-plus is vulnerable to Remote Code Execution (RCE) in versions 0.1.0 - 10.1.0. | 0.1.0 - 10.1.0 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
jsep Version ^1.4.0 | — | — |
@jsep-plugin/regex Version ^1.0.4 | — | — |
@jsep-plugin/assignment Version ^1.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant