← Zurück zur CVE-Suche

CVE-2026-48713

i18next

Beschreibung

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware-s missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key string on the configured keySeparator (default .) before calling the internal setPath() walker. The walker (getLastOfPath in lib/utils.js) did not guard against unsafe segments, so a key like -__proto__.polluted- was split into [-__proto__-, -polluted-] and walked straight into Object.prototype, allowing an attacker to write arbitrary properties onto the global object prototype. Depending on the host application, polluted prototype properties may cause crashes, corrupted translation behaviour, configuration poisoning, or bypasses of property-based security checks. Applications are affected only if the missingKeyHandler (or another route that forwards untrusted request bodies to i18next.t(..., { ... }) with saveMissin...

CVSS 9.1EPSS 0.41900000000000004%Risiko 0.94
Quelle öffnen
Veröffentlicht
2026-06-15 22:16:17
Betroffene Versionen
< 2.6.6
Typ
Bibliothek
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H