Repository navigation
Reject __proto__ as a flat messages() code, closing a sibling of GHSA-gg4h-3hg2-grpc - #3151
Merged
Marsup merged 1 commit intoSep 11, 2026
Conversation
…-gg4h-3hg2-grpc compile()/merge() in lib/messages.js were patched in GHSA-6w3j-5fw6-r9vr so a language named __proto__ can no longer overwrite the global Object.prototype. Both functions have a second write path that fix didn't reach: the flat, non-language error-code branch (target[code] = message / target[code] = new Template(message)). A top-level messages() key of __proto__ mapped to a string or template replaces the returned messages object's own prototype, the same confined-impact class already fixed for rename() in GHSA-gg4h-3hg2-grpc, in a sibling function that fix never touched. A language-scoped sub-key named __proto__ has the identical issue one level deeper. Reject __proto__ at each flat-write site in both compile() and merge(), mirroring the approach already used for rename(). New PoC test file locks in the fix at the Messages module level and through the public .messages()/.prefs() API. Full suite (1837 tests) passes after. Issue: hapijs#3150
daggerstuff
added a commit
to daggerstuff/pixelated
that referenced
this pull request
Sep 24, 2026
* chore(deps): bump joi 17.13.4 -> 17.13.8 Replaces the production-patches bump from the deleted dependabot branch (#6051): joi 17.13.5-17.13.8 carry the messages proto-injection guard (hapijs/joi#3151) and the isoDate timeshift padding fix (hapijs/joi#3143). Co-Authored-By: Claude Code <noreply@anthropic.com> * fix(deps): bump joi override pin to 17.13.8 The pnpm-workspace overrides pin joi: 17.13.4 was superseding the manifest ^17.13.8 bump from the major-updates merge (#6053), making the new version dead-letter and breaking the frozen lockfile check. Co-Authored-By: Claude Code <noreply@anthropic.com> * fix(deps): keep joi@17.13.4 resolvable for transitive pins px-cli's install still resolves joi@17.13.4 (some tooling pins the exact patch). Re-add its package + snapshot entries alongside 17.13.8. Co-Authored-By: Claude Code <noreply@anthropic.com> --------- Co-authored-by: Dagger <dagger@users.noreply.github.com> Co-authored-by: Claude Code <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #3150.
Summary
compile()/merge()inlib/messages.jswere patched in GHSA-6w3j-5fw6-r9vr so a language named__proto__can no longer overwrite the globalObject.prototype. Both functions have a second write path that fix didn't reach: the flat, non-language error-code branch (target[code] = message/target[code] = new Template(message)). A top-levelmessages()key of__proto__mapped to a string or template replaces the returned messages object's own prototype, the same confined-impact class already fixed forrename()in GHSA-gg4h-3hg2-grpc, in a sibling function that fix never touched. A language-scoped sub-key named__proto__has the identical issue one level deeper.Fix
Reject
__proto__at each flat-write site in bothcompile()andmerge(), mirroring the approach already used forrename().New PoC test file (
test/messages_proto_poc.js) locks in the fix at theMessagesmodule level and through the public.messages()/.prefs()API. Full suite (1837 tests) passes after.