Impact
The vulnerability is a prototype pollution flaw in the messages compilation step of the Joi validation library. It allows an attacker to supply __proto__ keys in a custom error message, which then replaces the prototype of the returned error object. This manipulation can alter or overwrite Object.prototype properties, potentially breaking any downstream code that relies on the original prototype behavior, such as object property access or method existence checks.
Affected Systems
The issue affects all releases of the Joi library with versions earlier than 17.13.8 and 18.2.9 from the hapijs organization. Systems that depend on these older packages and create custom validation error messages are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.3, indicating a moderate severity. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the issue is not listed in the CISA KEV catalog. Attackers can trigger the flaw by supplying crafted input that includes __proto__ keys in custom error messages, a vector that is feasible via. Successful exploitation can compromise application logic and stability by modifying the global Object prototype.
OpenCVE Enrichment