Vulnerability GHSA-wr44-6hxh-3jwq
Low Risk
LOW RISK
CVSS Score: 3.7
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
22 days ago
September 13, 2026 at 12:31 PM UTC
joi messages compilation allows prototype replacement through __proto__ error codes
0.0.1 - 17.13.7 and 18.0.0 - 18.2.8
0.0.1 - 17.13.7 and 18.0.0 - 18.2.8
Summary
joi messages compilation allows prototype replacement through __proto__ error codes
Details
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts proto as an error code. Attackers can supply proto keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
6 days ago
joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`
17.2.0 - 17.13.6 and 18.0.0 - 18.2.5 GHSA-6h2x-m376-mqjq
17.2.0 - 17.13.6 and 18.0.0 - 18.2.5 GHSA-6h2x-m376-mqjq
Low Risk
27 days ago
joi: Prototype pollution via a `__proto__` language key in custom messages
17.2.0 - 17.13.5 and 18.0.0 - 18.2.4 GHSA-6w3j-5fw6-r9vr
17.2.0 - 17.13.5 and 18.0.0 - 18.2.4 GHSA-6w3j-5fw6-r9vr
Low Risk
27 days ago
joi: object().rename() with a template target can set the validated object's prototype
17.1.1 - 17.13.4 and 18.0.0 - 18.2.3 GHSA-gg4h-3hg2-grpc
17.1.1 - 17.13.4 and 18.0.0 - 18.2.3 GHSA-gg4h-3hg2-grpc
Medium Risk
3 months ago
joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas
0.0.1 - 17.13.3 and 18.0.0 - 18.2.0 GHSA-q7cg-457f-vx79
0.0.1 - 17.13.3 and 18.0.0 - 18.2.0 GHSA-q7cg-457f-vx79
Impacted packages
Timeline
Published
22 days ago
September 13, 2026 at 12:31 PM UTC
Fixed (18.2.9)
24 days ago
September 11, 2026 at 01:31 PM UTC
Fixed (17.13.8)
Unknown
Unknown
Last Modified
7 hours ago
October 05, 2026 at 11:45 PM UTC