VDB
Sign up
MEDIUM6.1

GHSA-cmh5-qc8w-xvcq

Cross-Site Scripting in i18next

Quick fix

GHSA-cmh5-qc8w-xvcq — i18next: upgrade to the fixed version with the command below.

npm install i18next@3.4.4

Details

Affected versions of `i18next` may fail to sanitize user input when certain configuration options are used. When using the `.init` method, passing interpolation options without passing an `escapeValue` will default to `undefined` rather than the assumed `true`.

## Proof of Concept

```js var init = i18n.init({ interpolation: { prefix: "__", suffix: "__", escapeValue: true } }, function(){ var test = i18n.t('__firstName__ __lastName__', { firstName: 'Bob', lastName: '["foo","bar"]', }); console.log(test); }); ``` When `escapeValue` is explicitly passed, the result of `test` is:

```html <script>alert(1)</script> Johnson ```

This is supposed to be the default. However, if `escapeValue` is not included, the result is the unescaped string: ```html <script>alert(1)</script> Johnson ```

## Recommendation

Update to version 3.4.4 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/i18next
Introduced in: 2.0.0Fixed in: 3.4.4
Fixnpm install i18next@3.4.4

References