CVE-2026-84368
### Impact An application that passes attacker-controlled data into joi's custom message configuration (`messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`) lets the attacker write properties onto `Object.prototype`, where every object in the process then inherits them. A key named `__proto__` was treated as a language name, and the code reused the object it found at that key, which resolves to the prototype rather than to a new own property; a key named `constructor` did the same to the `Object` function's statics. A consuming application that gates on the mere presence of a property (`if (user.isAdmin)`) can be made to take the wrong branch for every object it inspects. This is not reachable from data that joi validates. Custom messages are schema-construction configuration, normally written by the application developer. Exploitation therefore requires an application that feeds untrusted input straight into schema construction. ### Patches Upgrade to version 18.2.5 or 17.13.6. ### Workarounds Do not pass untrusted input into `messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`. Or validate that they don't contain any `__proto__` or `constructor` property.
Properties
- summary
- joi: Prototype pollution via a `__proto__` language key in custom messages
- severity
- low
- epss_score
- 0.00255
- cvss_score
- 3.7
- ghsa_published
- 2026-09-08T20:55:58Z
- source_url
- https://github.com/advisories/GHSA-6w3j-5fw6-r9vr
- ghsa_updated
- 2026-09-08T20:56:00Z
- ghsa_id
- GHSA-6w3j-5fw6-r9vr
- cve_id
- CVE-2026-84368
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.16996
Related Entities (7)
ENRICHED_BY (1)
REPORTED_BY (1)
VULNERABLE_TO (2)
AFFECTS (2)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph