GHSA-wr44-6hxh-3jwqMediumCVSS 3.7

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the...

Published
September 13, 2026
Last Modified
September 13, 2026

🔗 CVE IDs covered (1)

📋 Description

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts proto as an error code. Attackers can supply proto keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.

🔗 References (7)