VYPR
Medium severity6.1NVD Advisory· Published May 29, 2018· Updated Jun 17, 2026

CVE-2017-16010

CVE-2017-16010

Description

i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This vulnerability affects i18next 2.0.0 and later.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
i18nextnpm
>= 2.0.0, < 3.4.43.4.4

Affected products

2
  • ghsa-coords
    Range: >= 2.0.0, < 3.4.4
  • HackerOne/i18next node modulev5
    Range: >=2.0.0 <=3.4.3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.