Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-14052
  • npm/require-i18next
Malicious code in require-i18next (npm) 15 Aug
  • No fix available
MAL-2026-12768
  • npm/devplatform-spa-plugin-i18next
Malicious code in devplatform-spa-plugin-i18next (npm) 05 Aug
  • No fix available
MAL-2026-12769
  • npm/devplatform-spa-plugin-i18next-instance
Malicious code in devplatform-spa-plugin-i18next-instance (npm) 05 Aug
  • No fix available
GHSA-2933-q333-qg83
  • npm/i18next-fs-backend
i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string 25 Jun
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-f49m-vf83-692w
  • npm/i18next-http-middleware
i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names 25 Jun
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-jfgf-83c5-2c4m
  • npm/i18next-http-middleware
i18next-http-middleware has path traversal / SSRF via user-controlled language and namespace parameters 29 Apr
  • Fix available
  • Severity - 8.2 (High)
GHSA-mgcp-mfp8-3q45
  • npm/i18next-locize-backend
i18next-locize-backend has URL Injection via Unsanitized Path Parameters 22 Apr
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-c3h8-g69v-pjrg
  • npm/i18next-http-middleware
i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header 22 Apr
  • Fix available
  • Severity - 8.6 (High)
GHSA-8847-338w-5hcj
  • npm/i18next-fs-backend
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite 22 Apr
  • Fix available
  • Severity - 8.2 (High)
GHSA-q89c-q3h5-w34g
  • npm/i18next-http-backend
i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns 22 Apr
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-5fgg-jcpf-8jjw
  • npm/i18next-http-middleware
i18next-http-middleware: Prototype pollution and path traversal via user-controlled language and namespace parameters 22 Apr
  • Fix available
  • Severity - 8.6 (High)
MAL-2025-190741
  • npm/@ensdomains/vite-plugin-i18next-loader
Malicious code in @ensdomains/vite-plugin-i18next-loader (npm) 24 Nov 2025
  • No fix available
MAL-2025-47539
  • npm/@sev-ui-verse/i18next-config
Malicious code in @sev-ui-verse/i18next-config (npm) 25 Sep 2025
  • No fix available
MAL-2025-22869
  • npm/i18next-xlsx-to-json
Malicious code in i18next-xlsx-to-json (npm) 14 Aug 2025
  • No fix available
MAL-2024-10770
  • npm/prettier-plugin-kimi-i18next
Malicious code in prettier-plugin-kimi-i18next (npm) 15 Nov 2024
  • No fix available
MAL-2023-8398
  • npm/@tpci/i18next-ext
Malicious code in @tpci/i18next-ext (npm) 24 Oct 2023
  • No fix available