Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-27307

29
FAUCET Score

CVE-2024-27307 is a critical vulnerability affecting JSONata versions 1.4.0 through 1.8.6 and 2.0.0 through 2.0.3. It allows a malicious JSONata expression to override core JavaScript Object properties via the transform operator. This can lead to severe impacts including denial of service, remote code execution, or other unexpected application behavior. With a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector, low attack complexity, and requires no user interaction, making it highly exploitable with complete confidentiality, integrity, and availability impacts. Organizations using user-provided JSONata expressions are particularly at risk. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. Patches are available in JSONata versions 1.8.7 and 2.0.4, and immediate updates are strongly recommended for affected applications.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.4.0, < 1.8.7CPE matchmatch criteria
cpe:2.3:a:jsonata:jsonata:*:*:*:*:*:*:*:*
>= 2.0.0, < 2.0.4CPE matchmatch criteria
cpe:2.3:a:jsonata:jsonata:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.42%
Probability of exploitation in next 30 days
EPSS Percentile
70.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0142 is in the 57th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: jsonataFixed in: 1.8.7
npmpatch availablevia ghsa
Product: jsonataFixed in: 2.0.4
redhatpatch availablevia redhat_api
Product: Red Hat Developer Hub 1.2 on RHEL 9Fixed in: rhdh/rhdh-hub-rhel9:1.2-105
View patch

Vendor Advisories (2)

redhatCVE-2024-27307Important

jsonata: malicious expression can pollute the "Object" prototype

Mar 6, 2024
npmGHSA-fqg8-vfv7-8fj8critical

JSONata expression can pollute the "Object" prototype

Mar 4, 2024

References

github.com / jsonata-js/jsonata/commit/1d579dbe99c19fbe509f5ba2c6db7959b0d456d1
Patch
github.com / jsonata-js/jsonata/commit/335d38f6278e96c908b24183f1c9c90afc8ae00c
Patch
github.com / jsonata-js/jsonata/commit/c907b5e517bb718015fcbd993d742ba6202f2be2
Patch
github.com / jsonata-js/jsonata/releases/tag/v2.0.4
ProductRelease Notes
github.com / jsonata-js/jsonata/security/advisories/GHSA-fqg8-vfv7-8fj8
Technical DescriptionVendor Advisory