cbcvebase.

Jsonata-Js Jsonata vulnerabilities

6 known vulnerabilities affecting jsonata-js/jsonata.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-77415P2CRITICALCVSS 9.3fixed in 1.8.8v>= 2.0.0, < 2.2.12026-08-21
CVE-2026-77415 [CRITICAL] CWE-94 CVE-2026-77415: JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expre JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects through evaluateTransformExpression, expose and deconstruct JSONata functions or lambdas through $merge.*, replace pr
nvd
CVE-2026-77413P2CRITICALCVSS 9.3fixed in 2.2.02026-08-21
CVE-2026-77413 [CRITICAL] CWE-94 CVE-2026-77413: JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression could use inherited prototype setters and getters, constructor access, valu
nvd
CVE-2024-27307P3CRITICALCVSS 9.8v>= 1.4.0, < 1.8.7v>= 2.0.0, < 2.0.42024-03-06
CVE-2024-27307 [CRITICAL] CWE-1321 CVE-2024-27307: JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that eval
nvd
CVE-2026-77414P3CRITICALCVSS 9.3fixed in 1.8.8v>= 2.0.0, < 2.2.12026-08-21
CVE-2026-77414 [CRITICAL] CWE-94 CVE-2026-77414: JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js en JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototype access, and $constructor to reach the object prototype and invoke process.getBuiltinModule with child_process
nvd
CVE-2026-52746P3HIGHCVSS 7.5v>= 2.0.0, < 2.2.0fixed in 1.8.92026-07-17
CVE-2026-52746 [HIGH] CWE-1333 CVE-2026-52746: JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matchin JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications that evaluate user-provided JSONata expressions. This issue is fixed in version 2.2.0 and 1.8.9.
nvd
CVE-2026-12208P3MEDIUMCVSS 5.3v2.0v2.1+1 more2026-06-15
CVE-2026-12208 [MEDIUM] CWE-94 CVE-2026-12208: A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the functi A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes. It is possible to initiate the attack remotely. The exploit has been m
nvd
Jsonata-Js Jsonata vulnerabilities | cvebase