CVE-2026-77415
published 2026-08-21CVE-2026-77415: JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to…
PriorityP261critical9.3CVSS 4.0
AVNACLATNPRNUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.65%
49.1th percentile
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects through evaluateTransformExpression, expose and deconstruct JSONata functions or lambdas through $merge.*, replace proc.arguments.forEach used by applyProcedure, and forge internal lambda state. These primitives allowed an attacker to reach prototype getters, prototype and constructor access, and process.getBuiltinModule with child_process, executing code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jsonata-js | jsonata | < 1.8.8 | 1.8.8 |
| jsonata-js | jsonata | — | — |
| jsonata | jsonata | >= 0 < 1.8.8 | 1.8.8 |
| jsonata | jsonata | >= 2.0.0 < 2.2.1 | 2.2.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
ghsa·2026-08-21
CVE-2026-77415 [CRITICAL] CWE-94 JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with
crafted expressions, due to:
- overwriting `$clone` allowing mutation of objects via transforms (see
[`evaluateTransformExpression`](https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/src/jsonata.js#L1304-L1314))
- it being possible to destruct jsonata functions/lambdas (e.g. `$merge.*`)
- [applyProcedure](https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/src/jsonata.js#L1670C20-L1675)
using `proc.arguments.forEach` and not `Array.prototype.forEach`
Which could be chained to execute arbitrary code.
This was fixed with:
- https://github.com/jsonata-js/jsonata/pul
VulDB
jsonata-js JSONata up to 1.8.7/2.2.0 evaluateTransformExpression $clone state issue
vuldb·2026-08-21·CVSS 9.3
CVE-2026-77415 [CRITICAL] jsonata-js JSONata up to 1.8.7/2.2.0 evaluateTransformExpression $clone state issue
A vulnerability identified as critical has been detected in jsonata-js JSONata up to 1.8.7/2.2.0. The affected element is the function evaluateTransformExpression. The manipulation of the argument $clone leads to state issue.
This vulnerability is referenced as CVE-2026-77415. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jsonata-js/jsonata/commit/47c0e58542202c705726663166dbee5fcae47d06https://github.com/jsonata-js/jsonata/commit/4b217d514376e30cba278941298d7ba97c4a6c6ehttps://github.com/jsonata-js/jsonata/commit/59e25144fc3b7125f6befd71b8a6e14e1fa610d2https://github.com/jsonata-js/jsonata/commit/f09df8416eab8ff44926fc6527c80fb8701de159https://github.com/jsonata-js/jsonata/commit/f174348c7fa30f271b63ddedf0767e814004bc4dhttps://github.com/jsonata-js/jsonata/pull/799https://github.com/jsonata-js/jsonata/pull/800https://github.com/jsonata-js/jsonata/pull/802https://github.com/jsonata-js/jsonata/releases/tag/v1.8.8https://github.com/jsonata-js/jsonata/releases/tag/v2.2.1https://github.com/jsonata-js/jsonata/security/advisories/GHSA-66mm-25pp-rfffhttps://github.com/jsonata-js/jsonata/security/advisories/GHSA-66mm-25pp-rfff
2026-08-21
Published