VDB
Sign up
MEDIUM6.1

GHSA-f89g-whpf-6q9m

Cross-Site Scripting in i18next

Quick fix

GHSA-f89g-whpf-6q9m — i18next: upgrade to the fixed version with the command below.

npm install i18next@1.10.3

Details

Affected versions of `i18next` allow untrusted user input to be injected into dictionary key names, resulting in a cross-site scripting vulnerability.

## Proof of Concept ```js var init = i18n.init({debug: true}, function(){ var test = i18n.t('__firstName__ __lastName__', { escapeInterpolation: true, firstName: '__lastNameHTML__', lastName: '<script>', }); console.log(test); }); // equals "<script> &lt;script&gt;" ```

## Recommendation

Update to version 1.10.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/i18next
Introduced in: 0Fixed in: 1.10.3
Fixnpm install i18next@1.10.3

References