VYPR

npm package

jsonata

pkg:npm/jsonata

Vulnerabilities (2)

  • CVE-2026-12208MedJun 15, 2026
    affected < 1.8.8fixed 1.8.8

    A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes

  • CVE-2024-27307CriMar 6, 2024
    affected >= 1.4.0, < 1.8.7fixed 1.8.7

    JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote