GHSA-6w3j-5fw6-r9vr

    Dashboard / Vulnerabilities / GHSA-6w3j-5fw6-r9vr

    GHSA-6w3j-5fw6-r9vr

    Published: 8 Sept 2026Last Modified: 8 Sept 2026

    Summary: joi: Prototype pollution via a `__proto__` language key in custom messages

    Details: ### Impact An application that passes attacker-controlled data into joi's custom message configuration (`messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`) lets the attacker write properties onto `Object.prototype`, where every object in the process then inherits them. A key named `__proto__` was treated as a language name, and the code reused the object it found at that key, which resolves to the prototype rather than to a new own property; a key named `constructor` did the same to the `Object` function's statics. A consuming application that gates on the mere presence of a property (`if (user.isAdmin)`) can be made to take the wrong branch for every object it inspects. This is not reachable from data that joi validates. Custom messages are schema-construction configuration, normally written by the application developer. Exploitation therefore requires an application that feeds untrusted input straight into schema construction. ### Patches Upgrade to version 18.2.5 or 17.13.6. ### Workarounds Do not pass untrusted input into `messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`. Or validate that they don't contain any `__proto__` or `constructor` property.

    Affected packages

    Package

    Name: joi

    Purl: pkg:npm/joi

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 17.2.0
    Fixed -17.13.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High