THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-66mm-25pp-rfff (critical) — JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions

[GHSA] GHSA-66mm-25pp-rfff (critical) — JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions

highgithub_advisoriesPublished 2026-08-21

GHSA-66mm-25pp-rfff Severity: critical CVE: CVE-2026-77415

JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions

Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to: - overwriting `$clone` allowing mutation of objects via transforms (see [`evaluateTransformExpression`](https://github.com/jsonata-js/jsonata/blob/8e

Indicators of compromise

Original source: https://github.com/advisories/GHSA-66mm-25pp-rfff