CVE-2026-77413Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression could use inherited prototype setters and getters, constructor access, valueOf, and process.getBuiltinModule to reach the child_process module and execute arbitrary code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-21); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-21: 1Mentions · 2026-08-22: 1Patch / Workaround · 2026-08-22: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-22: 108-2108-22
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - JSONata Prototype Pollution to RCE via lookup() (CVE-2026-77413) JSONata’s expression evaluator lookup() misses an Object.prototype.hasOwnProperty check, letting attacker-supplied expressions resolve inherited prototype members. Crafted JSONata can reach constructor/getters to access process.getBuiltinModule('child_process') and execute OS commands with host process privileges. 👉Affected: jsonata < 1.8.8 and >= 2.0.0 < 2.2.0 | Upgrade to 1.8.8 / 2.2.0

    Post summary

    A critical prototype‑pollution vulnerability (CVE‑2026‑77413) in JSONata allows RCE; affected versions are listed and the required upgrade is specified.

    0000067
    291 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-77413 Arbitrary Code Execution in JSONata via Prototype Pollution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-77413

    Post summary

    The post announces CVE-2026-77413 as an arbitrary code execution flaw in JSONata driven by prototype pollution, without providing PoC, exploit code, patch details, or evidence of active exploitation.

    00000121
    4.1K followersView on X

Explore more