Skip to content

Reject __proto__ as a flat messages() code, closing a sibling of GHSA-gg4h-3hg2-grpc - #3151

Merged
Marsup merged 1 commit into
hapijs:masterfrom
carfeii:fix/messages-flat-code-proto-pollution
Sep 11, 2026
Merged

Marsup merged 1 commit into
hapijs:masterfrom
carfeii:fix/messages-flat-code-proto-pollution

Conversation

@carfeii

@carfeii carfeii commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Fixes #3150.

Summary

compile()/merge() in lib/messages.js were patched in GHSA-6w3j-5fw6-r9vr so a language named __proto__ can no longer overwrite the global Object.prototype. Both functions have a second write path that fix didn't reach: the flat, non-language error-code branch (target[code] = message / target[code] = new Template(message)). A top-level messages() key of __proto__ mapped to a string or template replaces the returned messages object's own prototype, the same confined-impact class already fixed for rename() in GHSA-gg4h-3hg2-grpc, in a sibling function that fix never touched. A language-scoped sub-key named __proto__ has the identical issue one level deeper.

Fix

Reject __proto__ at each flat-write site in both compile() and merge(), mirroring the approach already used for rename().

New PoC test file (test/messages_proto_poc.js) locks in the fix at the Messages module level and through the public .messages()/.prefs() API. Full suite (1837 tests) passes after.

…-gg4h-3hg2-grpc

compile()/merge() in lib/messages.js were patched in GHSA-6w3j-5fw6-r9vr
so a language named __proto__ can no longer overwrite the global
Object.prototype. Both functions have a second write path that fix
didn't reach: the flat, non-language error-code branch (target[code] =
message / target[code] = new Template(message)). A top-level messages()
key of __proto__ mapped to a string or template replaces the returned
messages object's own prototype, the same confined-impact class already
fixed for rename() in GHSA-gg4h-3hg2-grpc, in a sibling function that
fix never touched. A language-scoped sub-key named __proto__ has the
identical issue one level deeper.

Reject __proto__ at each flat-write site in both compile() and merge(),
mirroring the approach already used for rename(). New PoC test file
locks in the fix at the Messages module level and through the public
.messages()/.prefs() API. Full suite (1837 tests) passes after.

Issue: hapijs#3150
@Marsup Marsup self-assigned this Sep 11, 2026
@Marsup Marsup added the bug Bug or defect label Sep 11, 2026
@Marsup Marsup added this to the 18.2.9 milestone Sep 11, 2026
@Marsup
Marsup merged commit 03a9543 into hapijs:master Sep 11, 2026
9 checks passed
Marsup added a commit that referenced this pull request Sep 11, 2026
Marsup added a commit that referenced this pull request Sep 11, 2026
pull Bot pushed a commit to TheDegenerateDev5150/joi that referenced this pull request Sep 11, 2026
daggerstuff added a commit to daggerstuff/pixelated that referenced this pull request Sep 24, 2026
* chore(deps): bump joi 17.13.4 -> 17.13.8

Replaces the production-patches bump from the deleted dependabot branch
(#6051): joi 17.13.5-17.13.8 carry the messages proto-injection guard
(hapijs/joi#3151) and the isoDate timeshift padding fix (hapijs/joi#3143).

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(deps): bump joi override pin to 17.13.8

The pnpm-workspace overrides pin joi: 17.13.4 was superseding the
manifest ^17.13.8 bump from the major-updates merge (#6053), making the
new version dead-letter and breaking the frozen lockfile check.

Co-Authored-By: Claude Code <noreply@anthropic.com>

* fix(deps): keep joi@17.13.4 resolvable for transitive pins

px-cli's install still resolves joi@17.13.4 (some tooling pins the exact
patch). Re-add its package + snapshot entries alongside 17.13.8.

Co-Authored-By: Claude Code <noreply@anthropic.com>

---------

Co-authored-by: Dagger <dagger@users.noreply.github.com>
Co-authored-by: Claude Code <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Bug or defect

Projects

None yet

Development

Successfully merging this pull request may close these issues.

messages(): __proto__ as a flat message code still hijacks the returned object's prototype (sibling of GHSA-gg4h-3hg2-grpc)

2 participants