Description
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.
Published: 2026-09-13
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Prototype Pollution
Action: Upgrade
AI Analysis

Impact

The vulnerability is a prototype pollution flaw in the messages compilation step of the Joi validation library. It allows an attacker to supply __proto__ keys in a custom error message, which then replaces the prototype of the returned error object. This manipulation can alter or overwrite Object.prototype properties, potentially breaking any downstream code that relies on the original prototype behavior, such as object property access or method existence checks.

Affected Systems

The issue affects all releases of the Joi library with versions earlier than 17.13.8 and 18.2.9 from the hapijs organization. Systems that depend on these older packages and create custom validation error messages are at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.3, indicating a moderate severity. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the issue is not listed in the CISA KEV catalog. Attackers can trigger the flaw by supplying crafted input that includes __proto__ keys in custom error messages, a vector that is feasible via. Successful exploitation can compromise application logic and stability by modifying the global Object prototype.

Generated by OpenCVE AI on September 21, 2026 at 00:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Joi to version 17.13.8 or later
  • Validate and sanitize custom error messages to remove or reject __proto__ keys before processing
  • Regularly check for and apply later updates from the hapijs vendor

Generated by OpenCVE AI on September 21, 2026 at 00:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-915
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 13 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Hapijs
Hapijs joi
Vendors & Products Hapijs
Hapijs joi

Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.
Title joi before 17.13.8 and 18.2.9 Prototype Pollution via messages
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:52.339Z

Reserved: 2026-09-13T10:14:57.680Z

Link: CVE-2026-90771

cve-icon Vulnrichment

Updated: 2026-09-16T14:03:13.405Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T11:17:01.613

Modified: 2026-09-24T20:44:42.207

Link: CVE-2026-90771

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-13T10:45:42Z

Links: CVE-2026-90771 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes