LOWVulnerability
CVE-2026-90771
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.
Properties
- severity
- LOW
- score
- 3.7
- cve_id
- CVE-2026-90771
- signal_observed_at
- 2026-09-23T04:35:40+00:00
- vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- published_at
- 2026-09-13T11:17:01.613
- last_modified
- 2026-09-16T15:18:42.280
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph