VYPR
Medium severity6.1NVD Advisory· Published Jun 4, 2018· Updated Jun 17, 2026

CVE-2017-16008

CVE-2017-16008

Description

i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next <=1.10.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
i18nextnpm
< 1.10.31.10.3

Affected products

2
  • ghsa-coords
    Range: < 1.10.3
  • HackerOne/i18next node modulev5
    Range: <=1.10.2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.