JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototype access, and $constructor to reach the object prototype and invoke process.getBuiltinModule with child_process, executing arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.1.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Aug 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jsonata-js
Jsonata-js jsonata |
|
| Vendors & Products |
Jsonata-js
Jsonata-js jsonata |
Fri, 21 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototype access, and $constructor to reach the object prototype and invoke process.getBuiltinModule with child_process, executing arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.1. | |
| Title | JSONata: Arbitrary Code Execution via crafted JSONata expressions | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-21T20:51:43.500Z
Reserved: 2026-08-20T19:55:27.024Z
Link: CVE-2026-77414
No data.
Status : Received
Published: 2026-08-21T21:17:07.410
Modified: 2026-08-21T21:17:07.410
Link: CVE-2026-77414
No data.
OpenCVE Enrichment
Updated: 2026-08-21T22:45:04Z