PT-2026-79488 · Npm · Jsonata
CVE-2026-77415
·
Published
2026-07-13
·
Updated
2026-08-21
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JSONata versions prior to 1.8.8
JSONata versions prior to 2.2.1
Description
Crafted JSONata expressions can chain multiple object-integrity weaknesses to achieve arbitrary code execution with the privileges of the host process. The attack chain involves overwriting
$clone to mutate objects via evaluateTransformExpression, exposing and deconstructing functions or lambdas through $merge.*, replacing proc.arguments.forEach used by applyProcedure, and forging internal lambda state. These actions allow access to prototype getters, prototype and constructor access, and process.getBuiltinModule with child process.Recommendations
Update to version 1.8.8 or later.
Update to version 2.2.1 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jsonata