Vulnerability GHSA-wr44-6hxh-3jwq

Low Risk
LOW RISK
CVSS Score: 3.7
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
22 days ago
September 13, 2026 at 12:31 PM UTC
joi messages compilation allows prototype replacement through __proto__ error codes
0.0.1 - 17.13.7 and 18.0.0 - 18.2.8
0.0.1 - 17.13.7 and 18.0.0 - 18.2.8

Summary

joi messages compilation allows prototype replacement through __proto__ error codes

Details

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts proto as an error code. Attackers can supply proto keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.

Impacted packages

Timeline

Published
22 days ago
September 13, 2026 at 12:31 PM UTC
Fixed (18.2.9)
24 days ago
September 11, 2026 at 01:31 PM UTC
Fixed (17.13.8)
Unknown
Unknown
Last Modified
7 hours ago
October 05, 2026 at 11:45 PM UTC