PT-2026-79488 · Npm · Jsonata

CVE-2026-77415

·

Published

2026-07-13

·

Updated

2026-08-21

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JSONata versions prior to 1.8.8 JSONata versions prior to 2.2.1
Description Crafted JSONata expressions can chain multiple object-integrity weaknesses to achieve arbitrary code execution with the privileges of the host process. The attack chain involves overwriting $clone to mutate objects via evaluateTransformExpression, exposing and deconstructing functions or lambdas through $merge.*, replacing proc.arguments.forEach used by applyProcedure, and forging internal lambda state. These actions allow access to prototype getters, prototype and constructor access, and process.getBuiltinModule with child process.
Recommendations Update to version 1.8.8 or later. Update to version 2.2.1 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12628
CVE-2026-77415
GHSA-66MM-25PP-RFFF

Affected Products

Jsonata