THREAT OPS › Threat News › [GHSA] GHSA-gg4h-3hg2-grpc (low) — joi: object().rename() with a template target can set the validated object's prototype
[GHSA] GHSA-gg4h-3hg2-grpc (low) — joi: object().rename() with a template target can set the validated object's prototype
GHSA-gg4h-3hg2-grpc Severity: low CVE: CVE-2026-84367
joi: object().rename() with a template target can set the validated object's prototype
### Impact
Applications are affected only if a schema renames keys with a regular-expression source and a `Joi.expression()` / `Joi.x()` target that interpolates the pattern's own match data, combined with `{ multiple: true }`, for example `.rename(/^x-(.+
Indicators of compromise
- CVE-2026-84367cve
Original source: https://github.com/advisories/GHSA-gg4h-3hg2-grpc