CVE-2026-90771: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in hapijs joi
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.
AI Analysis
Technical Summary
The vulnerability in hapijs joi before versions 17.13.8 and 18.2.9 allows an attacker to supply __proto__ keys in custom messages. This leads to prototype pollution by replacing the prototype of the returned object. The issue resides in the messages compilation function, which does not properly control modification of object prototype attributes. This can break code that depends on standard Object.prototype behavior.
Potential Impact
An attacker can manipulate the prototype of objects returned by the messages compilation function, potentially causing unexpected behavior or logic errors in applications relying on Object.prototype methods. This could lead to application instability or security issues depending on how the polluted prototype is leveraged. The CVSS score of 6.3 indicates a medium severity impact with network attack vector, high attack complexity, and no privileges or user interaction required.
Mitigation Recommendations
Upgrading to hapijs joi versions 17.13.8 or later, or 18.2.9 or later, addresses this vulnerability. Users should apply these official fixes to remediate the prototype pollution issue. No other mitigation steps are indicated by the vendor advisory.
CVE-2026-90771: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in hapijs joi
Description
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.
CVSS v4.0
Score 6.3medium
Affected software
hapijs
joi
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in hapijs joi before versions 17.13.8 and 18.2.9 allows an attacker to supply __proto__ keys in custom messages. This leads to prototype pollution by replacing the prototype of the returned object. The issue resides in the messages compilation function, which does not properly control modification of object prototype attributes. This can break code that depends on standard Object.prototype behavior.
Potential Impact
An attacker can manipulate the prototype of objects returned by the messages compilation function, potentially causing unexpected behavior or logic errors in applications relying on Object.prototype methods. This could lead to application instability or security issues depending on how the polluted prototype is leveraged. The CVSS score of 6.3 indicates a medium severity impact with network attack vector, high attack complexity, and no privileges or user interaction required.
Mitigation Recommendations
Upgrading to hapijs joi versions 17.13.8 or later, or 18.2.9 or later, addresses this vulnerability. Users should apply these official fixes to remediate the prototype pollution issue. No other mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-13T10:14:57.680Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa682ac55bf5e2cf583e18e
Added to database: 09/13/2026, 11:02:04 UTC
Last enriched: 09/13/2026, 11:17:29 UTC
Last updated: 09/14/2026, 02:25:35 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.