joi: object().rename() with a template target can set the validated object's prototype
Published Sep 1, 2026
3.7
LOWCVSS 3.1
EPSS 0.39%
Description
joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permits a schema that renames keys with a regular-expression source and a Joi.expression() or Joi.x() target that interpolates the pattern's own match data, combined with { multiple: true }, to derive a target from an attacker-controlled input key. An attacker can send x-__proto__ with an object value, causing the target to render as __proto__ and set the prototype of the object returned by validate() instead of creating an own key. The global Object.prototype is not modified, so the effect is confined to the object returned by that validation call. Static-string targets and schemas using the default { multiple: false } are not affected. This issue is fixed in versions 17.13.5 and 18.2.4.
Affected products
-
- Version >= 16.0.0, < 17.13.5StatusaffectedConstraints-
- Version >= 18.0.0, < 18.2.4StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
joi
npm
Introduced 16.0.0 Fixed 17.13.5joi
npm
Introduced 18.0.0 Fixed 18.2.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | joi | 16.0.0 | 17.13.5 |
| npm | joi | 18.0.0 | 18.2.4 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 3, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Sep-Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.39% (0.00389) | 30.65th | v5 (v2026.06.15) |
| Sep 2, 2026 | 0.27% (0.00270) | 18.82th | v5 (v2026.06.15) |
References (9)
- https://github.com/advisories/GHSA-gg4h-3hg2-grpc Advisory
- https://github.com/hapijs/joi/commit/162f367aa178d2e1ebec8dc1164e5fe16536ddf6 x_refsource_MISC
- https://github.com/hapijs/joi/commit/172ececa192feda532b743d77bc9d3e523d19b01 x_refsource_MISC
- https://github.com/hapijs/joi/pull/3134 x_refsource_MISC
- https://github.com/hapijs/joi/pull/3135 x_refsource_MISC
- https://github.com/hapijs/joi/releases/tag/v17.13.5
- https://github.com/hapijs/joi/releases/tag/v18.2.4
- https://github.com/hapijs/joi/security/advisories/GHSA-gg4h-3hg2-grpc x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-84367
Change history (0)
No recorded changes yet.