criticalVulnerability

CVE-2026-77415

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects through evaluateTransformExpression, expose and deconstruct JSONata functions or lambdas through $merge.*, replace proc.arguments.forEach used by applyProcedure, and forge internal lambda state. These primitives allowed an attacker to reach prototype getters, prototype and constructor access, and process.getBuiltinModule with child_process, executing code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.1.

Properties

severity
critical
summary
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
epss_score
0.00892
retrieved_at
2026-10-04T19:49:43+00:00
ghsa_published
2026-08-21T21:04:19Z
source_url
https://github.com/advisories/GHSA-66mm-25pp-rfff
ghsa_updated
2026-08-21T21:04:20Z
ghsa_id
GHSA-66mm-25pp-rfff
last_source
FIRST EPSS
cve_id
CVE-2026-77415
signal_observed_at
2026-09-11T17:54:59+00:00
is_ghsa_only
false
published_at
2026-08-21T21:17:07.553
last_modified
2026-09-09T21:06:39.057
epss_percentile
0.58034

Related Entities (6)

DESCRIBED_BY (1)

→[Source]NVD

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]npm/jsonata

AFFECTS (1)

→[Software]npm/jsonata

HAS_WEAKNESS (1)

→[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph