PT-2024-2194 · Jsonata · Jsonata
Albertspedersen
·
Published
2024-02-28
·
Updated
2025-12-04
·
CVE-2024-27307
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JSONata versions 1.4.0 through 1.8.6
JSONata versions 2.0.0 through 2.0.3
Description
A malicious expression can use the transform operator to override properties on the
Object constructor and prototype, potentially leading to denial of service, remote code execution, or other unexpected behavior in applications that evaluate user-provided JSONata expressions.Recommendations
For JSONata versions 1.4.0 through 1.8.6, update to version 1.8.7 or later to prevent exploitation.
For JSONata versions 2.0.0 through 2.0.3, update to version 2.0.4 or later to prevent exploitation.
As a temporary workaround, consider applying the manual patch provided to prevent exploitation.
Exploit
Fix
DoS
RCE
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jsonata