CVE-2026-1615Disclosure

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. An attacker can exploit this vulnerability by supplying a malicious JSON Path expression that, when evaluated, executes arbitrary JavaScript code, leading to Remote Code Execution in Node.js environments or Cross-site Scripting (XSS) in browser contexts. This affects all methods that evaluate JSON Paths against objects, including .query, .nodes, .paths, .value, .parent, and .apply.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-09); latest day: 2
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-02-09: 4Mentions · 2026-02-10: 2Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-10: 2Technical Details · 2026-02-09: 4Technical Details · 2026-02-10: 202-0902-10
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-094
Disclosure3Patch1
2026-02-102
Disclosure1Patch1
Full discourse6 posts
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Web Services Stack (CVSS 9.8-9.9) Affected: jsonpath (npm); GitLab AI Gateway; Lighttpd Internet-facing risks dominate, driven by pre-auth and unauthenticated exploits across a JSON-path library, a gateway service, and a web server. CVE-2026-1868 (CVSS 9.9) GitLab AI Gateway Duo Workflow Service is affected by insecure template expansion of user-supplied Duo Agent Platform Flow definitions across AI Gateway versions 18.1.6 through 18.8.0, enabling potential DoS or code execution. CVE-2026-1615 (CVSS 9.8) All versions of jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. CVE-2026-22903 (CVSS 9.8) A modified lighttpd server can be triggered by an unauthenticated remote attacker sending a crafted HTTP request with an overly long SESSIONID cookie, causing a stack buffer overflow that can crash the service and may enable remote code execution. CVE-2026-22904 (CVSS 9.8) Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated attacker to send oversized cookie values that trigger a stack buffer overflow, leading to denial of service and potential remote code execution. 🛠️ Action • Patch/upgrade GitLab AI Gateway to 18.6.2, 18.7.1, or 18.8.1 (per advisory) and apply vendor updates for impacted components when available • Prioritize internet-facing instances and edge deployments for rapid remediation • For jsonpath (CVE-2026-1615) with no fix yet, apply mitigations such as avoiding evaluation of untrusted JSONPath expressions or sandboxing input; monitor for patches • Add detections for exploitation patterns: suspicious JSONPath input attempts and anomalous script execution in eval paths; monitor relevant logs • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    Three critical CVEs (CVE‑2026‑1868, CVE‑2026‑1615, CVE‑2026‑22903/22904) affecting GitLab AI Gateway, jsonpath, and lighttpd are disclosed with high CVSS scores, detailed vulnerability mechanisms, and patch/mitigation guidance.

    00010105
    64 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1615 All versions of the package jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the … https://www.cve.org/CVERecord?id=CVE-2026-1615

    Post summary

    CVE-2026-1615 exposes an arbitrary code injection flaw in the jsonpath package by unsafely evaluating user‑supplied JSON Path expressions, but no proof‑of‑concept, exploit, patch, or active exploitation information is provided.

    00010333
    56.5K followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 Critical CVEs Today: Web Services Stack (CVSS 9.8-9.9) Affected: jsonpath (npm); GitLab AI Gateway; Lighttpd Internet-facing risks dominate, driven by pre-auth and unauthenticated exploits across a JSON-path library, a gateway service, and a web server. CVE-2026-1868 (CVSS 9.9) GitLab AI Gateway Duo Workflow Service is affected by insecure template expansion of user-supplied Duo Agent Platform Flow definitions across AI Gateway versions 18.1.6 through 18.8.0, enabling potential DoS or code execution. CVE-2026-1615 (CVSS 9.8) All versions of jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. CVE-2026-22903 (CVSS 9.8) A modified lighttpd server can be triggered by an unauthenticated remote attacker sending a crafted HTTP request with an overly long SESSIONID cookie, causing a stack buffer overflow that can crash the service and may enable remote code execution. CVE-2026-22904 (CVSS 9.8) Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated attacker to send oversized cookie values that trigger a stack buffer overflow, leading to denial of service and potential remote code execution. 🛠️ Action • Patch/upgrade GitLab AI Gateway to 18.6.2, 18.7.1, or 18.8.1 (per advisory) and apply vendor updates for impacted components when available • Prioritize internet-facing instances and edge deployments for rapid remediation • For jsonpath (CVE-2026-1615) with no fix yet, apply mitigations such as avoiding evaluation of untrusted JSONPath expressions or sandboxing input; monitor for patches • Add detections for exploitation patterns: suspicious JSONPath input attempts and anomalous script execution in eval paths; monitor relevant logs • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces three high‑CVSS critical CVEs, provides technical details and recommended patches, but does not mention PoCs, exploit code, or active exploitation.

    0000080
    64 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1615: CRITICAL] Vulnerability alert: jsonpath package is susceptible to Arbitrary Code Injection through unsafe JSON Path evaluation, leading to Remote Code Execution or XSS attacks in Node.js and br...#cve,CVE-2026-1615,#cybersecurity https://cvefind.com/CVE-2026-1615

    Post summary

    An alert describing CVE-2026-1615 as a critical vulnerability in the jsonpath package that allows arbitrary code injection and can lead to remote code execution or XSS on Node.js, with no patch or exploit details disclosed.

    0000075
    583 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: All jsonpath versions let attackers inject code via unsafe JSON Path evaluation. RCE & XSS risk in Node.js & browsers. Audit dependencies & avoid untrusted input now! https://radar.offseq.com/threat/cve-2026-1615-arbitrary-code-injection-in-jsonpath-a64ac077 #OffSe... https://t.co/Dzep1rYDY7

    Post summary

    The tweet warns about CVE‑2026‑1615, a critical JSONPath flaw that permits RCE and XSS, and urges users to audit dependencies and avoid untrusted input as a mitigation.

    0000060
    268 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1615 - Critical All versions of the package jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module t... https://www.thehackerwire.com/vulnerability/CVE-2026-1615/ https://t.co/cj8bLsr7wZ

    Post summary

    The post discloses a critical arbitrary code injection flaw affecting all versions of the jsonpath library via unsafe evaluation of user‑supplied JSON Path expressions, but it does not provide a PoC, exploit code, or patch information.

    0000066
    112 followersView on X

Explore more