jsonata
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting jsonatapage 1 of 1
- CVE-2024-27307CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.0.42024-03-06
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. Th…
- CVE-2026-52746HIGHCVSS 7.5EG 7.5✓ Fixed in 1.8.92026-07-02
JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in app…
- CVE-2026-77413CRITICALCVSS 9.3EG 9.3✓ Fixed in 1.8.82026-08-21
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An a…
- CVE-2026-77414CRITICALCVSS 9.3EG 9.3✓ Fixed in 2.2.12026-08-21
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototyp…
- CVE-2026-77415CRITICALCVSS 9.3EG 9.3✓ Fixed in 2.2.12026-08-21
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects throug…
Check whether jsonata is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for jsonata CVEs against the assets you own.
Start Free Scan →