CVE-2026-12208
published 2026-06-15CVE-2026-12208: A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component…
PriorityP335medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.31%
24.5th percentile
A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cryostat | cryostat-grafana-dashboard-rhel9 | — | — |
| jsonata-js | jsonata | — | — |
| jsonata-js | jsonata | — | — |
| jsonata-js | jsonata | — | — |
| jsonata | jsonata | — | — |
| jsonata | jsonata | >= 0 < 1.8.8 | 1.8.8 |
| jsonata | jsonata | >= 2.0.0 < 2.2.1 | 2.2.1 |
| openshift-serverless-1 | kn-eventing-integrations-aws-ddb-streams-source-rhel9 | — | — |
| openshift-serverless-1 | kn-eventing-integrations-aws-s3-sink-rhel9 | — | — |
| openshift-serverless-1 | kn-eventing-integrations-aws-s3-source-rhel9 | — | — |
| openshift-serverless-1 | kn-eventing-integrations-aws-sns-sink-rhel9 | — | — |
| openshift-serverless-1 | kn-eventing-integrations-aws-sqs-sink-rhel9 | — | — |
| openshift-serverless-1 | kn-eventing-integrations-aws-sqs-source-rhel9 | — | — |
| openshift-serverless-1 | kn-eventing-integrations-log-sink-rhel9 | — | — |
| openshift-serverless-1 | kn-eventing-integrations-timer-source-rhel9 | — | — |
| openshift-serverless-1 | kn-eventing-integrations-transform-jsonata-rhel9 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
jsonata: Function Binding Prototype Pollution via hasOwnProperty Override
ghsa·2026-06-15
CVE-2026-12208 [MEDIUM] CWE-94 jsonata: Function Binding Prototype Pollution via hasOwnProperty Override
jsonata: Function Binding Prototype Pollution via hasOwnProperty Override
A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA
A weakness has been identified in jsonata-js jsonata up to 2.2.0.
ghsa_unreviewed·2026-06-15
CVE-2026-12208 [MEDIUM] CWE-94 A weakness has been identified in jsonata-js jsonata up to 2.2.0.
A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
VulDB
jsonata-js jsonata up to 2.2.0 Function Binding Frame System src/jsonata.js createFrame prototype pollution
vuldb·2026-06-14
CVE-2026-12208 [CRITICAL] jsonata-js jsonata up to 2.2.0 Function Binding Frame System src/jsonata.js createFrame prototype pollution
A vulnerability has been found in jsonata-js jsonata up to 2.2.0 and classified as critical. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes.
The identification of this vulnerability is CVE-2026-12208. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
Red Hat
jsonata: jsonata-js jsonata Function Binding Frame System jsonata.js createFrame prototype pollution
vendor_redhat·2026-06-15·CVSS 5.3
CVE-2026-12208 [MEDIUM] CWE-915 jsonata: jsonata-js jsonata Function Binding Frame System jsonata.js createFrame prototype pollution
jsonata: jsonata-js jsonata Function Binding Frame System jsonata.js createFrame prototype pollution
A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A flaw was found in the jsonata JavaScript library. A prototype pollution vulnerability exists in the createFrame function in src/jsonata.js, allowing a remote attacker to manipulate object prototype a
No detection rules found.
No public exploits indexed.
2026-06-15
Published