• Sources: GitHub advisory GHSA-66mm-25pp-rfff, GitHub advisory GHSA-2943-5xfg-gq5f, GitHub advisory GHSA-8gq3-vp5j-2grp, JSONata 2.2.1 release
  • Summary: Three separate advisories, each rated CVSS v4 9.3, describe an escape from JSONata's expression evaluation that reaches arbitrary code execution in the host process, and the advisory texts carry working proof-of-concept expressions. The affected ranges are >= 2.0.0, < 2.2.1 and < 1.8.8 for the two linked above, and <= 1.8.7 plus >= 2.0.0, < 2.2.0 for the third, GHSA-8gq3-vp5j-2grp and CVE-2026-77413, which this run found through the advisories API. The patches are older than the advisories: 2.2.1 was released on 2026-05-19 and 1.8.8 on 2026-07-16, and the advisories were published in the jsonata-js/jsonata repository on 2026-07-13. What happened on 2026-08-21, within a few minutes of each other from 20:57 UTC, is that all three entries reached the GitHub Advisory Database.
  • Why it matters: A service that evaluates a user-supplied JSONata expression on a version below 2.2.1 or 1.8.8 hands the sender code execution in the host process, and 2.2.0 is not enough, because it clears CVE-2026-77413 and leaves the other two.

send feedback on this story