PT-2026-49170 · Npm · Jsonata-Js
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
jsonata-js jsonata versions prior to 2.2.1
Description
A weakness in the Function Binding Frame System component allows for prototype pollution, which is the improperly controlled modification of object prototype attributes. This issue occurs within the
createFrame() function located in the src/jsonata.js file and can be triggered remotely.Recommendations
Update to a version later than 2.2.0.
As a temporary workaround, restrict the use of the
createFrame() function to minimize the risk of exploitation.Exploit
Fix
Prototype Pollution
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jsonata-Js