StackRadar

CVE-2026-1615

Critical

Advisory

Published 9 Feb 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.011
63rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
1 of 1
affected package

jsonpath has Arbitrary Code Injection via Unsafe Evaluation of JSON Path Expressions

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
jsonpathnpm0.2.12, 1.0.0, 1.0.1, 1.0.2+1 more1.3.019
OSV records
GHSA-87r5-mp6g-5w5j

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
kubeflowkubeflow1.6.21 of 45See more

kubeflow kubeflow 1.6.2

1 of the 45 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
jsonpath@1.0.1
1.3.0

Open the chart page →

96,941
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
jsonpath@1.1.1
1.3.0

Open the chart page →

7,776
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
jsonpath@1.1.1
1.3.0

Open the chart page →

2,851
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
jsonpath@1.1.1
1.3.0

Open the chart page →

4,260
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
jsonpath@1.1.1
1.3.0

Open the chart page →

12,581
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
jsonpath@1.0.2
1.3.0

Open the chart page →

25,456
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
jsonpath@1.1.1
1.3.0

Open the chart page →

5,488
swagger-combine-uicryptexlabsVerified publisher0.2.41 of 1See more

swagger-combine-ui cryptexlabs 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
jsonpath@0.2.12
1.3.0

Open the chart page →

1,378
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
jsonpath@1.1.1
1.3.0

Open the chart page →

9,019
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
jsonpath@1.0.2
1.3.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
jsonpath@1.0.2
1.3.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
jsonpath@1.0.0
1.3.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
jsonpath@1.0.0
1.3.0

Open the chart page →

89,959
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
jsonpath@1.0.0
1.3.0

Open the chart page →

39,349
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
jsonpath@1.1.1
1.3.0

Open the chart page →

11,812
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
jsonpath@1.1.1
1.3.0

Open the chart page →

6,454
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
jsonpath@1.1.1
1.3.0

Open the chart page →

5,287
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
jsonpath@1.1.1
1.3.0

Open the chart page →

17,929
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-1615.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
jsonpath@1.1.1
1.3.0

Open the chart page →

5,497

Container images carrying it

19 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
jsonpath@0.2.12
1.3.0
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
jsonpath@1.1.1
1.3.0
1
ianw/quickchart:v1.7.1dc49dd460c37
jsonpath@1.1.1
1.3.0
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
jsonpath@1.0.0
1.3.0
1
jayfong/yapi:1.10.2163e5d621910
jsonpath@1.1.1
1.3.0
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
jsonpath@1.0.1
1.3.0
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
jsonpath@1.1.1
1.3.0
1
library/ghost:4.37.0767230c0f263
jsonpath@1.1.1
1.3.0
1
library/ghost:5.79.083f7bf209844
jsonpath@1.1.1
1.3.0
1
n8nio/n8n:0.212.0a9195bc499a3
jsonpath@1.1.1
1.3.0
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
jsonpath@1.1.1
1.3.0
1
zooz/predator:1.6f491d1f7a865
jsonpath@1.1.1
1.3.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
jsonpath@1.0.2
1.3.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
jsonpath@1.0.2
1.3.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
jsonpath@1.0.0
1.3.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
jsonpath@1.0.0
1.3.0
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
jsonpath@1.1.1
1.3.0
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
jsonpath@1.1.1
1.3.0
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
jsonpath@1.0.2
1.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.