jsonata
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting jsonatapage 1 of 1
- CVE-2024-27307CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.0.42024-03-06
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. Th…
- CVE-2026-52746HIGHCVSS 7.5EG 7.5✓ Fixed in 2.2.02026-07-02
JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications …
Check whether jsonata is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for jsonata CVEs against the assets you own.
Start Free Scan →