CVE-2026-12208 | jsonata-js jsonata up to 2.2.0 Function Binding Frame System src/jsonata.js createFrame prototype pollution

SecurityVulns

A vulnerability has been found in jsonata-js jsonata up to 2.2.0 and classified as critical. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype attributes.

The identification of this vulnerability is CVE-2026-12208. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More