EXECUTIVE SUMMARY:
The three vulnerabilities affect the JSONata npm package and describe multiple arbitrary code execution vulnerabilities in the expression evaluation engine. Crafted JSONata expressions could bypass security controls and abuse internal functions, prototype-related behavior, and JSONata lambdas to reach JavaScript functionality and execute arbitrary operating-system commands. The vulnerabilities can allow attackers to execute arbitrary commands on the underlying system.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
The three vulnerabilities affect the JSONata npm package and describe multiple arbitrary code execution vulnerabilities in the expression evaluation engine. Crafted JSONata expressions could bypass security controls and abuse internal functions, prototype-related behavior, and JSONata lambdas to reach JavaScript functionality and execute arbitrary operating-system commands. The vulnerabilities can allow attackers to execute arbitrary commands on the underlying system.[emaillocker id="1283"]
CVE-2026-77413 (CVSS 9.3 — Critical): A vulnerability in JSONata allows attackers to execute arbitrary code through crafted expressions due to a missing hasOwnProperty check in the lookup function, potentially enabling command execution.
CVE-2026-77414 (CVSS 9.3 — Critical): A vulnerability in JSONata allows attackers to execute arbitrary code through crafted expressions by bypassing the hasOwnProperty check in environment.lookup, potentially enabling command execution.
CVE-2026-77415 (CVSS 9.3 — Critical): A vulnerability in JSONata allows attackers to execute arbitrary code through crafted expressions by manipulating $clone, JSONata functions/lambdas, and applyProcedure, which can be chained to achieve command execution.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-8gq3-vp5j-2grp
https://github.com/advisories/GHSA-2943-5xfg-gq5f
https://github.com/advisories/GHSA-66mm-25pp-rfff