CVE-2026-77415Critical▾ MidnightJSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects thro…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.5%
Last analysed / modified upstream
0.5% → 0.6%
JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects through evaluateTransformExpression, expose and deconstruct JSONata functions or lambdas through $merge.*, replace proc.arguments.forEach used by applyProcedure, and forge internal lambda state. These primitives allowed an attacker to reach prototype getters, prototype and constructor access, and process.getBuiltinModule with child_process, executing code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
jsonata >= 2.0.0, < 2.2.1jsonata < 1.8.8Patched in:
jsonata 2.2.1jsonata 1.8.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-12208Medium· 5.3jsonata: Function Binding Prototype Pollution via hasOwnProperty Override
CVE-2026-77414CriticalJSONata is a JSON query and transformation language
CVE-2026-77413CriticalJSONata is a JSON query and transformation language
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick
CVE-2026-52746High· 7.5jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
CVE-2025-13786High· 7.3A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665