lowCVSS 3.7Vulnerability

CVE-2026-84368

### Impact An application that passes attacker-controlled data into joi's custom message configuration (`messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`) lets the attacker write properties onto `Object.prototype`, where every object in the process then inherits them. A key named `__proto__` was treated as a language name, and the code reused the object it found at that key, which resolves to the prototype rather than to a new own property; a key named `constructor` did the same to the `Object` function's statics. A consuming application that gates on the mere presence of a property (`if (user.isAdmin)`) can be made to take the wrong branch for every object it inspects. This is not reachable from data that joi validates. Custom messages are schema-construction configuration, normally written by the application developer. Exploitation therefore requires an application that feeds untrusted input straight into schema construction. ### Patches Upgrade to version 18.2.5 or 17.13.6. ### Workarounds Do not pass untrusted input into `messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`. Or validate that they don't contain any `__proto__` or `constructor` property.

Properties

summary
joi: Prototype pollution via a `__proto__` language key in custom messages
severity
low
epss_score
0.00255
cvss_score
3.7
ghsa_published
2026-09-08T20:55:58Z
source_url
https://github.com/advisories/GHSA-6w3j-5fw6-r9vr
ghsa_updated
2026-09-08T20:56:00Z
ghsa_id
GHSA-6w3j-5fw6-r9vr
cve_id
CVE-2026-84368
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
is_ghsa_only
false
epss_percentile
0.16996

Related Entities (7)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (2)

[Software]npm/joi
[Software]npm/@hapi/joi

AFFECTS (2)

[Software]npm/joi
[Software]npm/@hapi/joi

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84368 (CVSS 3.7) — Ninja Signal Threat Intelligence | Ninja Signal