Object Integrity Vulnerability in JSONata from JSONata-js
CVE-2026-77415
9.3CRITICAL
What is CVE-2026-77415?
An object integrity vulnerability in JSONata allows crafted expressions to exploit weak security measures, enabling attackers to execute arbitrary code within the context of the host process. By chaining multiple weaknesses, an attacker can compromise the integrity of objects, manipulate internal states, and gain unauthorized access to sensitive functionalities. This vulnerability was addressed in versions 1.8.8 and 2.2.1, which implement necessary fixes to mitigate these risks.
Affected Version(s)
jsonata < 1.8.8 < 1.8.8
jsonata >= 2.0.0, < 2.2.1 < 2.0.0, 2.2.1
