i18next Prototype Pollution Flaw (CVSS 9.1) Threatens 1M+ Weekly Downloads
ID: c8760471-8df6-5b2d-a11c-a55230149fe1
STIX ID: report--c8760471-8df6-5b2d-a11c-a55230149fe1
Feed Name: securityonline.info
A critical prototype pollution vulnerability (CVE-2026-48713, CVSS 9.1) in i18next / i18next-fs-backend (≤2.6.5) allows unauthenticated attackers to write properties to Object.prototype via crafted missing-translation keys; exploitation requires specific configurations (missing-key persistence exposed to untrusted users and default key splitting). Maintain ers released a fix in i18next-fs-backend 2.6.6 and recommend upgrading or disabling missing-key persistence / key splitting until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
