CVE-2026-77414
published 2026-08-21CVE-2026-77414: JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty…
PriorityP355critical9.3CVSS 4.0
AVNACLATNPRNUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.43%
36.8th percentile
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototype access, and $constructor to reach the object prototype and invoke process.getBuiltinModule with child_process, executing arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jsonata-js | jsonata | < 1.8.8 | 1.8.8 |
| jsonata-js | jsonata | — | — |
| jsonata | jsonata | >= 0 < 1.8.8 | 1.8.8 |
| jsonata | jsonata | >= 2.0.0 < 2.2.1 | 2.2.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
jsonata-js JSONata up to 1.8.7/2.2.0 src/jsonata.js environment.lookup prototype pollution
vuldb·2026-08-21·CVSS 9.3
CVE-2026-77414 [CRITICAL] jsonata-js JSONata up to 1.8.7/2.2.0 src/jsonata.js environment.lookup prototype pollution
A vulnerability described as critical has been identified in jsonata-js JSONata up to 1.8.7/2.2.0. The affected element is the function environment.lookup of the file src/jsonata.js. The manipulation results in improperly controlled modification of object prototype attributes.
This vulnerability is cataloged as CVE-2026-77414. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
ghsa·2026-08-21
CVE-2026-77414 [CRITICAL] CWE-94 JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with
crafted expressions, due to a bypassable `hasOwnProperty` check in
`environment.lookup`
https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/src/jsonata.js#L1863-L1871
This was fixed in https://github.com/jsonata-js/jsonata/pull/799
(https://github.com/jsonata-js/jsonata/pull/799/files#diff-de23c1b6e199d0e59406a284aae5fa7be63fcbbff706829913dba73dcdeb061cL1865-R1865)
which is included in the `2.2.1` release, and then back-ported to the `1.8.8` release.
## PoC
```js
import jsonata from "jsonata";
const expression = jsonata(`
(
$hasOwnProperty := $spread($string);
$__proto__ := $constructor;
$constr
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jsonata-js/jsonata/commit/59e25144fc3b7125f6befd71b8a6e14e1fa610d2https://github.com/jsonata-js/jsonata/pull/799https://github.com/jsonata-js/jsonata/releases/tag/v1.8.8https://github.com/jsonata-js/jsonata/releases/tag/v2.2.1https://github.com/jsonata-js/jsonata/security/advisories/GHSA-2943-5xfg-gq5fhttps://github.com/jsonata-js/jsonata/security/advisories/GHSA-2943-5xfg-gq5f
2026-08-21
Published