lowCVSS 3.7Vulnerability

CVE-2026-84367

### Impact Applications are affected only if a schema renames keys with a regular-expression source and a `Joi.expression()` / `Joi.x()` target that interpolates the pattern's own match data, combined with `{ multiple: true }`, for example `.rename(/^x-(.+)$/, Joi.x('{#1}'), { multiple: true })`. Because the target is rendered from the matched input key, an attacker who controls input keys can send `x-__proto__` with an object value and make the rename target render as `__proto__`, which sets the prototype of the object joi returns instead of creating a key on it. The global `Object.prototype` is not modified, so the effect is confined to the object returned by that one `validate()` call. Schemas using a static string rename target are not affected, and neither are schemas left on the default `{ multiple: false }`. ### Patches Versions 17.13.5 and 18.2.4 have been released to address the issue. ### Workarounds 1. Replace the template rename target with a static string target. 2. Keep the template but make the capture unable to produce `__proto__`, using a negative lookahead: `.rename(/^x-(?!__proto__$)(.+)$/, Joi.x('{#1}'), { multiple: true })` 3. Drop { multiple: true } from the rename, which stops the rename before the assignment.

Properties

summary
joi: object().rename() with a template target can set the validated object's prototype
severity
low
epss_score
0.0027
cvss_score
3.7
ghsa_published
2026-09-08T20:51:21Z
source_url
https://github.com/advisories/GHSA-gg4h-3hg2-grpc
ghsa_updated
2026-09-08T20:51:23Z
ghsa_id
GHSA-gg4h-3hg2-grpc
cve_id
CVE-2026-84367
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
is_ghsa_only
false
epss_percentile
0.18916

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/joi

AFFECTS (1)

[Software]npm/joi

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84367 (CVSS 3.7) — Ninja Signal Threat Intelligence | Ninja Signal