CVE-2026-90771: joi before 17.13.8 and 18.2.9 Prototype Pollution via messages
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts proto as an error code. Attackers can supply proto keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
joito a version that resolves this vulnerability.Fixed in 17.13.8 - Upgrade
Upgrade
joito a version that resolves this vulnerability.Fixed in 18.2.9