Intel

AIKIDO-2026-379323

@hapi/joi is vulnerable to Use of Unmaintained Third Party Components

Use of Unmaintained Third Party Components Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 27, 2026

50

Medium Risk

This Affects:

js@hapi/joi
0.0.0 - *
Are you affected? Scan for Free

TL;DR

The @hapi/joi package is no longer actively maintained as a standalone package. Its functionality has been incorporated into joi starting with version 17.1.1. The npm registry marks every published version of @hapi/joi as deprecated and directs users to install joi instead.

Who does this affect?

You are affected if you are using this package.

Background info

@hapi/joi is vulnerable to Use of Unmaintained Third Party Components in all versions.

How to fix this

Remove any @hapi/joi package from your application. Users should migrate to joi starting from v17.1.1.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform