PT-2026-79476 · Npm · Jsonata

CVE-2026-77414

·

Published

2026-07-13

·

Updated

2026-08-21

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JSONata versions prior to 1.8.8 JSONata versions prior to 2.2.1
Description The environment.lookup() function in src/jsonata.js uses a bypassable hasOwnProperty check. An attacker can use crafted expressions involving $hasOwnProperty, $spread, $string, prototype access, and $constructor to reach the object prototype and invoke process.getBuiltinModule with child process, leading to arbitrary code execution with the privileges of the host process.
Recommendations Update to version 1.8.8 or later. Update to version 2.2.1 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12627
CVE-2026-77414
GHSA-2943-5XFG-GQ5F

Affected Products

Jsonata