CVE-2026-12208Medium· 5.3▾ Sunlitjsonata: Function Binding Prototype Pollution via hasOwnProperty Override
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
jsonata < 1.8.8jsonata >= 2.0.0, < 2.2.1Upgrade to a patched release:
jsonata 1.8.8jsonata 2.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77414CriticalJSONata is a JSON query and transformation language
CVE-2026-77415CriticalJSONata is a JSON query and transformation language
CVE-2026-77413CriticalJSONata is a JSON query and transformation language
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2026-52746High· 7.5jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
CVE-2025-13786High· 7.3A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665