jsonata is vulnerable to Information Disclosure
53
Medium Risk
JSONata wildcard evaluation descends into ordinary objects and also traverses internal function and lambda representation objects. Expressions using * or ** can expose internal implementation fields from built-in functions, lambdas, or regular expression objects. This leaks internal evaluator structure that should not be observable through wildcard selection. The fix prevents wildcard and descendant traversal from unwrapping internal function objects.
You are affected if you are using a version that falls within the vulnerable range.
jsonata is vulnerable to Information Disclosure in versions 1.8.7 - 2.2.0.
Upgrade the jsonata library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant