CVE-2026-84367
### Impact Applications are affected only if a schema renames keys with a regular-expression source and a `Joi.expression()` / `Joi.x()` target that interpolates the pattern's own match data, combined with `{ multiple: true }`, for example `.rename(/^x-(.+)$/, Joi.x('{#1}'), { multiple: true })`. Because the target is rendered from the matched input key, an attacker who controls input keys can send `x-__proto__` with an object value and make the rename target render as `__proto__`, which sets the prototype of the object joi returns instead of creating a key on it. The global `Object.prototype` is not modified, so the effect is confined to the object returned by that one `validate()` call. Schemas using a static string rename target are not affected, and neither are schemas left on the default `{ multiple: false }`. ### Patches Versions 17.13.5 and 18.2.4 have been released to address the issue. ### Workarounds 1. Replace the template rename target with a static string target. 2. Keep the template but make the capture unable to produce `__proto__`, using a negative lookahead: `.rename(/^x-(?!__proto__$)(.+)$/, Joi.x('{#1}'), { multiple: true })` 3. Drop { multiple: true } from the rename, which stops the rename before the assignment.
Properties
- summary
- joi: object().rename() with a template target can set the validated object's prototype
- severity
- low
- epss_score
- 0.0027
- cvss_score
- 3.7
- ghsa_published
- 2026-09-08T20:51:21Z
- source_url
- https://github.com/advisories/GHSA-gg4h-3hg2-grpc
- ghsa_updated
- 2026-09-08T20:51:23Z
- ghsa_id
- GHSA-gg4h-3hg2-grpc
- cve_id
- CVE-2026-84367
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.18916
Related Entities (5)
ENRICHED_BY (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph