StackRadar

CVE-2025-1302

Critical

Advisory

Published 15 Feb 2025In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.104
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
54
of 17,781 indexed, latest versions
Container images
50
deployed by those charts
Fix available
1 of 1
affected package

JSONPath Plus allows Remote Code Execution

Carried by container images the latest versions of 54 of 17,781 indexed charts deploy, on 50 images.

Affected packageAffected versionsFixed inImages
jsonpath-plusnpm0.19.0, 3.0.0, 4.0.0, 6.0.1+3 more10.3.050
OSV records
GHSA-hw8r-x6gr-5gjp

Charts affected

54 by stars
ChartLatestAffected imagesRadar Score
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-1302.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
jsonpath-plus@6.0.1
10.3.0

Open the chart page →

5,604
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2025-1302.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
jsonpath-plus@0.19.0
10.3.0

Open the chart page →

2,838
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-1302.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
jsonpath-plus@7.2.0
10.3.0

Open the chart page →

1,341
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-1302.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
jsonpath-plus@0.19.0
10.3.0

Open the chart page →

1,752

Container images carrying it

50 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
jsonpath-plus@7.2.0
10.3.0
4
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
jsonpath-plus@0.19.0
10.3.0
2
mesosphere/kommander:6.100.13917e82333a9
jsonpath-plus@0.19.0
10.3.0
2
mojaloop/reporting:v12.1.0d480a62103d6
jsonpath-plus@0.19.0
10.3.0
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
jsonpath-plus@6.0.1
10.3.0
2
apimap/developer:v1.3.1406d3858e20c
jsonpath-plus@4.0.0
10.3.0
1
apimap/portal:v2.4.0041a4790c65c
jsonpath-plus@4.0.0
10.3.0
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
jsonpath-plus@0.19.0
10.3.0
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
jsonpath-plus@0.19.0
10.3.0
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
jsonpath-plus@0.19.0
10.3.0
1
coldatom/containers-security-api:latesteae9e82da080
jsonpath-plus@7.2.0
10.3.0
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
jsonpath-plus@3.0.0
10.3.0
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
jsonpath-plus@7.2.0
10.3.0
1
fanzynoodle/smeejas:0.0.15f9916c1a287
jsonpath-plus@0.19.0
10.3.0
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
jsonpath-plus@7.2.0
10.3.0
1
glenndehaan/api-mapper:latest6ff6310683bf
jsonpath-plus@7.2.0
10.3.0
1
glenndehaan/kube-hook:latest0a7116f48bfe
jsonpath-plus@10.2.0
10.3.0
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
jsonpath-plus@0.19.0
10.3.0
1
kubebb/component-store:latestfd8ecbd73213
jsonpath-plus@7.2.0
10.3.0
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
jsonpath-plus@7.2.0
10.3.0
1
kubevious/backend:1.2.22d9ba6eb46b6
jsonpath-plus@7.2.0
10.3.0
1
kubevious/parser:1.2.299ae7a5168c2
jsonpath-plus@7.2.0
10.3.0
1
kyleslugg/klusterview:latestba8c36dfdfbd
jsonpath-plus@7.2.0
10.3.0
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
jsonpath-plus@0.19.0
10.3.0
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
jsonpath-plus@8.1.0
10.3.0
1
neoskop/papergirl:3.2.67f52b5949f03
jsonpath-plus@7.2.0
10.3.0
1
pawelmalak/flame:2.1.193e7b0abb603
jsonpath-plus@0.19.0
10.3.0
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
jsonpath-plus@0.19.0
10.3.0
1
plumdog/db-operator:latest0c2fa2db0357
jsonpath-plus@0.19.0
10.3.0
1
redis/redisinsight:2.46699d341bd329
jsonpath-plus@6.0.1
10.3.0
1
roadiehq/community-backstage-image:latestef355bf5b639
jsonpath-plus@0.19.0
10.3.0
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
jsonpath-plus@6.0.1
10.3.0
1
ymuski/skooner:latest67819ca511b5
jsonpath-plus@0.19.0
10.3.0
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
jsonpath-plus@10.2.0
10.3.0
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
jsonpath-plus@10.2.0
10.3.0
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
jsonpath-plus@7.2.0
10.3.0
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
jsonpath-plus@7.2.0
10.3.0
1
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
jsonpath-plus@7.2.0
10.3.0
1
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
jsonpath-plus@7.2.0
10.3.0
1
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
jsonpath-plus@0.19.0
10.3.0
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
jsonpath-plus@0.19.0
10.3.0
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
jsonpath-plus@7.2.0
10.3.0
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
jsonpath-plus@7.2.0
10.3.0
1
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
jsonpath-plus@0.19.0
10.3.0
1
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
jsonpath-plus@0.19.0
10.3.0
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
jsonpath-plus@6.0.1
10.3.0
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
jsonpath-plus@10.2.0
10.3.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
jsonpath-plus@0.19.0
10.3.0
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
jsonpath-plus@0.19.0
10.3.0
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
jsonpath-plus@0.19.0
10.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.