jsonata@1.6.4 vulnerabilities

JSON query and transformation language

Direct Vulnerabilities

Known vulnerabilities in the jsonata package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Prototype Pollution

jsonata is a JSON query and transformation language

Affected versions of this package are vulnerable to Prototype Pollution due to the use of the transform operator to override properties on the Object constructor and prototype. An attack can lead to denial of service, remote code execution, or other unexpected behavior in applications that evaluate user-provided expressions by crafting malicious expressions.

How to fix Prototype Pollution?

Upgrade jsonata to version 1.8.7, 2.0.4 or higher.

>=1.4.0 <1.8.7 >=2.0.0 <2.0.4