CVE-2026-77413 | jsonata-js jsonata up to 1.8.7/2.1.x Lookup Function src/functions.js lookup code injection
A vulnerability marked as critical has been reported in jsonata-js jsonata up to 1.8.7/2.1.x. Impacted is the function lookup of the file src/functions.js of the component Lookup Function. The manipulation leads to code injection.
This vulnerability is listed as CVE-2026-77413. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.