THREAT OPS › Threat News › [GHSA] GHSA-6w3j-5fw6-r9vr (low) — joi: Prototype pollution via a `__proto__` language key in custom messages
[GHSA] GHSA-6w3j-5fw6-r9vr (low) — joi: Prototype pollution via a `__proto__` language key in custom messages
GHSA-6w3j-5fw6-r9vr Severity: low CVE: CVE-2026-84368
joi: Prototype pollution via a `__proto__` language key in custom messages
### Impact An application that passes attacker-controlled data into joi's custom message configuration (`messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`) lets the attacker write properties onto `Object.prototype`, wher
Indicators of compromise
- CVE-2026-84368cve
Original source: https://github.com/advisories/GHSA-6w3j-5fw6-r9vr