GHSA-wr44-6hxh-3jwq

Suggest an improvement
Source
https://github.com/advisories/GHSA-wr44-6hxh-3jwq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wr44-6hxh-3jwq/GHSA-wr44-6hxh-3jwq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wr44-6hxh-3jwq
Aliases
Downstream
MINI (6)
Published
2026-09-13T12:31:12Z
Modified
2026-10-05T23:45:08Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
joi messages compilation allows prototype replacement through __proto__ error codes
Details

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts proto as an error code. Attackers can supply proto keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.

Database specific
{
    "cwe_ids":  [
        "CWE-1321"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T23:29:52Z",
    "nvd_published_at":  "2026-09-13T11:17:01Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / joi

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
17.13.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wr44-6hxh-3jwq/GHSA-wr44-6hxh-3jwq.json"

npm / joi

Package

Affected ranges

Type
SEMVER
Events
Introduced
18.0.0
Fixed
18.2.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-wr44-6hxh-3jwq/GHSA-wr44-6hxh-3jwq.json"