Disclosure summary
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-wr44-6hxh-3jwq
Open original source · Updated Oct 05, 2026
joi messages compilation allows prototype replacement through __proto__ error codes
Source severity: MEDIUM / 6.3
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | joi | < 17.13.8 | 17.13.8 |
| npm | joi | >= 18.0.0, < 18.2.9 | 18.2.9 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-13T08:31:12-04:00
MODIFIED 2026-10-05T19:29:53-04:00
INGESTED 2026-10-06T11:45:33-04:00