THREAT OPS › Threat News › [GHSA] GHSA-8gq3-vp5j-2grp (critical) — JSONata: Arbitrary Code Execution via crafted JSONata expressions
[GHSA] GHSA-8gq3-vp5j-2grp (critical) — JSONata: Arbitrary Code Execution via crafted JSONata expressions
GHSA-8gq3-vp5j-2grp Severity: critical CVE: CVE-2026-77413
JSONata: Arbitrary Code Execution via crafted JSONata expressions
## Impact
Before JSONata `2.2.0` and `1.8.8` it was possible to execute arbitrary code with crafted expressions, due to a missing `hasOwnProperty` check in the `lookup` function: https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/funct
Indicators of compromise
- f9632e01e6e67d4f9f00593f9795420cb4b57f48sha1
- CVE-2026-77413cve
Original source: https://github.com/advisories/GHSA-8gq3-vp5j-2grp