The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
We have discovered 782 live websites that are affected by CVE-2025-61140.
| Product | |
| Category | JavaScript Libraries |
| Vulnerable Domains | 782 live websites (100% of jsonpath install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 2 versions ( 100% of all versions) |
| 269 websites | |
| 449 websites | |
| 14 websites | |
| 12 websites | |
| 10 websites | |
| 3 websites | |
| 3 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites |
| .com | 216 websites |
| .net | 4 websites |
| .co | 3 websites |
| .ch | 2 websites |
| .io | 2 websites |
| .com.cn | 1 websites |
| .eu | 1 websites |
| .nl | 1 websites |
| .se | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | **,*** | ||
| *******.com | ***,*** | ||
| **.**********.com | ***,*** | ||
| ********.***.tw | ***,*** | ||
| ******.***.tw | ***,*** | ||
| *************.tw | ***,*** | ||
| ****.***.***.tw | ***,*** | ||
| ********.***.tw | ***,*** | ||
| ****.******.***.tw | ***,*** | ||
| ****.******.***.tw | ***,*** |