Description
In JSONata versions >= 1.4.0, < 1.8.7 and >= 2.0.0, < 2.0.4, a malicious expression can use the transform operator to override properties on the Object constructor and prototype. This may lead to denial of service, remote code execution or other unexpected behavior in applications that evaluate user-provided JSONata expressions.
Recommendation
Update the jsonata package to the latest compatible version. Followings are version details:
Affected version(s): **>= 2.0.0, < 2.0.4 >= 1.4.0, < 1.8.7** Patched version(s): **2.0.4 1.8.7**
References
Related Issues
- protobufjs: Text Format string map parsing can mutate returned map object prototype - CVE-2026-59876
- Prototype pollution in ag-grid-community via the _.mergeDeep function - ag-grid-enterprise - CVE-2024-38996
- Prototype Pollution in madlib-object-utils - CVE-2022-24279
- Matrix IRC Bridge truncated content of messages can be leaked - CVE-2024-32000
You might also like:
- Tags:
- npm
- jsonata
Anything's wrong? Let us know Last updated on March 06, 2024


