criticalVulnerability

CVE-2026-77414

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototype access, and $constructor to reach the object prototype and invoke process.getBuiltinModule with child_process, executing arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.1.

Properties

severity
critical
summary
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
epss_score
0.0057
retrieved_at
2026-10-05T02:30:02+00:00
ghsa_published
2026-08-21T20:58:01Z
source_url
https://github.com/advisories/GHSA-2943-5xfg-gq5f
ghsa_updated
2026-08-21T20:58:02Z
ghsa_id
GHSA-2943-5xfg-gq5f
last_source
FIRST EPSS
cve_id
CVE-2026-77414
signal_observed_at
2026-09-11T17:54:59+00:00
is_ghsa_only
false
published_at
2026-08-21T21:17:07.410
last_modified
2026-09-09T21:06:39.057
epss_percentile
0.45215

Related Entities (6)

DESCRIBED_BY (1)

→[Source]NVD

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]npm/jsonata

AFFECTS (1)

→[Software]npm/jsonata

HAS_WEAKNESS (1)

→[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph