THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6w3j-5fw6-r9vr (low) — joi: Prototype pollution via a `__proto__` language key in custom messages

[GHSA] GHSA-6w3j-5fw6-r9vr (low) — joi: Prototype pollution via a `__proto__` language key in custom messages

medgithub_advisoriesPublished 2026-09-08

GHSA-6w3j-5fw6-r9vr Severity: low CVE: CVE-2026-84368

joi: Prototype pollution via a `__proto__` language key in custom messages

### Impact An application that passes attacker-controlled data into joi's custom message configuration (`messages()`, `message()`, `prefs({ messages })`, `Joi.extend({ messages })` or `rule({ message })`) lets the attacker write properties onto `Object.prototype`, wher

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6w3j-5fw6-r9vr