criticalVulnerability

CVE-2026-77413

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression could use inherited prototype setters and getters, constructor access, valueOf, and process.getBuiltinModule to reach the child_process module and execute arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.0.

Properties

severity
critical
summary
JSONata: Arbitrary Code Execution via crafted JSONata expressions
epss_score
0.00719
retrieved_at
2026-10-05T10:42:26+00:00
ghsa_published
2026-08-21T20:57:07Z
source_url
https://github.com/advisories/GHSA-8gq3-vp5j-2grp
ghsa_updated
2026-08-21T20:57:09Z
ghsa_id
GHSA-8gq3-vp5j-2grp
last_source
FIRST EPSS
cve_id
CVE-2026-77413
signal_observed_at
2026-09-11T17:54:59+00:00
is_ghsa_only
false
published_at
2026-08-21T21:17:07.267
last_modified
2026-09-09T21:06:39.057
epss_percentile
0.52248

Related Entities (6)

DESCRIBED_BY (1)

→[Source]NVD

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]npm/jsonata

AFFECTS (1)

→[Software]npm/jsonata

HAS_WEAKNESS (1)

→[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph