MEDIUM6.1
GHSA-f89g-whpf-6q9m
Cross-Site Scripting in i18next
Quick fix
GHSA-f89g-whpf-6q9m — i18next: upgrade to the fixed version with the command below.
npm install i18next@1.10.3Details
Affected versions of `i18next` allow untrusted user input to be injected into dictionary key names, resulting in a cross-site scripting vulnerability.
## Proof of Concept ```js var init = i18n.init({debug: true}, function(){ var test = i18n.t('__firstName__ __lastName__', { escapeInterpolation: true, firstName: '__lastNameHTML__', lastName: '<script>', }); console.log(test); }); // equals "<script> <script>" ```
## Recommendation
Update to version 1.10.3 or later.
Are you affected?
Enter the version of the package you're using.