VulnSea

jsonata vulnerabilities

CVEs whose affected-version data names the jsonata package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-77413Critical
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An…

Midnightjsonata · jsonataEPSS 0.52%via NVD
CVE-2026-77414Critical
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, protot…

Midnightjsonata · jsonataEPSS 0.43%via NVD
CVE-2026-77415Critical
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects thro…

Midnightjsonata · jsonataEPSS 0.65%via NVD
CVE-2026-52746High· 7.5
2mo ago

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

Twilightjsonata · jsonataEPSS 0.69%via GHSA
CVE-2026-12208Medium· 5.3
3mo ago

jsonata: Function Binding Prototype Pollution via hasOwnProperty Override

jsonata: Function Binding Prototype Pollution via hasOwnProperty Override

Sunlitjsonata · jsonataEPSS 0.31%via GHSA
jsonata vulnerabilities (CVEs) · VulnSea