Executive brief
jq is a popular command-line tool used for processing and transforming JSON data. A vulnerability in how it handles file imports allows an attacker to bypass security policies that restrict which files jq is allowed to access. In practice, this could allow sensitive data (like API keys or internal notes) to be accidentally included in public reports or software releases because the tool loaded a private configuration file instead of the intended public one.
Technical details
A semantic mismatch exists between jq's length-aware strings and the underlying C string operations used in src/linker.c. While the jq language level accepts strings with embedded NUL bytes (\u0000), the linker converts these to NUL-terminated C strings during module and data-file lookup. Functions such as validate_relpath(), find_lib(), and jv_load_file() truncate the path at the first NUL byte. This allows an attacker to craft an import string that passes prefix/suffix validation logic in a wrapper script (e.g., requiring a '_public' suffix) while jq actually resolves and opens a different file on disk. This is primarily a risk in CI/CD pipelines or automated sanitization workflows where jq filters are provided by less-trusted sources.
Affected products
- jqlang jq <= 1.8.1
Timeline
- 2026-05-09: advisory: GitHub Security Advisory published
- 2026-05-11: disclosed: CVE-2026-43895 published to NVD