External risk intelligence

JSONata Lookup Function Prototype Pollution Leads to Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-77413

JSONata is a library used to process JSON data within applications. While it can be incorporated into internet-facing web services that accept user-provided transformation queries, it is also frequently used in internal backend processing, build pipelines, or CLI tools where public internet reachability is not inherent.

Code Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability was identified in the JSONata processing library that could allow for the execution of arbitrary code if an attacker can supply a crafted expression. This impacts systems that use certain versions of the library to process JSON data. The primary concern is to confirm if this specific technology is in use and if it is exposed to the necessary conditions for an attack.

  • Crafted expressions allow arbitrary code execution.
  • Critical vulnerability in common JSON data processing.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker who can provide crafted JSONata expressions to a vulnerable application can exploit a flaw in how the `lookup` function handles object properties. By leveraging inherited prototype members, constructor access, or other mechanisms, an attacker could potentially execute arbitrary code on the host system with the same permissions as the running application.

  • Attacker supplies malicious expression.
  • Vulnerable function lacks prototype check.
  • Arbitrary code execution is possible.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a crafted JSONata expression could allow an attacker to execute arbitrary code with the privileges of the host process, potentially impacting the confidentiality, integrity, and availability of the system.

  • System data and application logic.
  • Supplying a crafted JSONata expression.
  • Arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The JSONata library, used for JSON query and transformation, has a critical vulnerability that allows for arbitrary code execution. Teams responsible for applications, platforms, or services that utilize JSONata for processing user-supplied expressions must act swiftly. The initial step involves identifying all instances of the affected JSONata versions, assessing their exposure and criticality, and locating the accountable owner before planning remediation.

  • Application and platform owners should manage the remediation.
  • Verify JSONata usage and expression input sources.
  • Plan upgrades or implement mitigating controls.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is JSONata and how is it used?

JSONata is a query and transformation language library designed for JSON data. Developers integrate it into their software to extract, reshape, and manipulate data structures. It is commonly embedded within web services, data processing pipelines, build tools, or command-line interfaces to handle complex JSON logic programmatically.

How does the CVE-2026-77413 vulnerability work?

This vulnerability is a form of code injection classified as CWE-94. It occurs because the library's lookup function fails to properly validate object properties, allowing access to inherited prototype members. By providing a malicious expression, an attacker can traverse these members to reach restricted system modules, such as child_process, and execute arbitrary commands on the underlying server.

Do I need to supply a malicious expression to trigger this bug?

Yes, an attacker must be able to input a crafted JSONata expression into the application for the flaw to be triggered. If your application processes JSONata queries using only hardcoded, internal, or trusted logic that cannot be influenced by external inputs, the conditions required to trigger this vulnerability are not present.

Why is this CVE relevant to my environment?

According to Halo Surface Signal, the risk level depends on your implementation. While JSONata is often used for safe internal backend tasks, it becomes highly critical if your application uses it to process user-supplied transformation queries. Services exposed to the internet that accept arbitrary expressions from users are at the highest risk of remote exploitation.

What are the first steps to address CVE-2026-77413?

Begin by auditing your dependency manifests to identify all applications utilizing JSONata versions prior to 1.8.8 or 2.2.0. Once you have a clear inventory of affected systems, prioritize those that accept untrusted input. Coordinate with your application owners to plan an update to the patched versions, which introduce the necessary security checks to prevent unauthorized access to prototype members.

References