GHSA-gg4h-3hg2-grpc

    Dashboard / Vulnerabilities / GHSA-gg4h-3hg2-grpc

    GHSA-gg4h-3hg2-grpc

    Published: 8 Sept 2026Last Modified: 8 Sept 2026

    Summary: joi: object().rename() with a template target can set the validated object's prototype

    Details: ### Impact Applications are affected only if a schema renames keys with a regular-expression source and a `Joi.expression()` / `Joi.x()` target that interpolates the pattern's own match data, combined with `{ multiple: true }`, for example `.rename(/^x-(.+)$/, Joi.x('{#1}'), { multiple: true })`. Because the target is rendered from the matched input key, an attacker who controls input keys can send `x-__proto__` with an object value and make the rename target render as `__proto__`, which sets the prototype of the object joi returns instead of creating a key on it. The global `Object.prototype` is not modified, so the effect is confined to the object returned by that one `validate()` call. Schemas using a static string rename target are not affected, and neither are schemas left on the default `{ multiple: false }`. ### Patches Versions 17.13.5 and 18.2.4 have been released to address the issue. ### Workarounds 1. Replace the template rename target with a static string target. 2. Keep the template but make the capture unable to produce `__proto__`, using a negative lookahead: `.rename(/^x-(?!__proto__$)(.+)$/, Joi.x('{#1}'), { multiple: true })` 3. Drop { multiple: true } from the rename, which stops the rename before the assignment.

    Affected packages

    Package

    Name: joi

    Purl: pkg:npm/joi

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 16.0.0
    Fixed -17.13.5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High