THREAT OPS › Threat News › [GHSA] GHSA-2943-5xfg-gq5f (critical) — JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
[GHSA] GHSA-2943-5xfg-gq5f (critical) — JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
GHSA-2943-5xfg-gq5f Severity: critical CVE: CVE-2026-77414
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Before JSONata `2.2.1` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a bypassable `hasOwnProperty` check in `environment.lookup` https://github.com/jsonata-js/jsonata/blob/8ee4476f8a228bfc7a62979ae0a9c13a4043cd03/src/js
Indicators of compromise
- 8ee4476f8a228bfc7a62979ae0a9c13a4043cd03sha1
- CVE-2026-77414cve
Original source: https://github.com/advisories/GHSA-2943-5xfg-gq5f