THREAT OPS › Threat News › [GHSA] GHSA-66mm-25pp-rfff (critical) — JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
[GHSA] GHSA-66mm-25pp-rfff (critical) — JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
GHSA-66mm-25pp-rfff Severity: critical CVE: CVE-2026-77415
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to: - overwriting `$clone` allowing mutation of objects via transforms (see [`evaluateTransformExpression`](https://github.com/jsonata-js/jsonata/blob/8e
Indicators of compromise
- 8ee4476f8a228bfc7a62979ae0a9c13a4043cd03sha1
- c41ef185136a7b96ca1049c7745a7503b82193desha1
- d49dcdd01a4617e5601edda3ce9a971a791126dcsha1
- e362dfd686c1dadd1dd9324373819be446fd4f04sha1
- CVE-2026-77415cve
Original source: https://github.com/advisories/GHSA-66mm-25pp-rfff