VYPR
Low severity3.7NVD Advisory· Published Sep 13, 2026

CVE-2026-90771

CVE-2026-90771

Description

joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.

Affected products

2
  • hapijs/Joireferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <17.13.8 and <18.2.9

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.