High severity7.2OSV Advisory· Published Aug 16, 2024· Updated Jun 17, 2026
CVE-2024-43370
CVE-2024-43370
Description
gettext.js is a GNU gettext port for node and the browser. There is a cross-site scripting (XSS) injection if .po dictionary definition files are corrupted. This vulnerability has been patched in version 2.0.3. As a workaround, control the origin of the definition catalog to prevent the use of this flaw in the definition of plural forms.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gettext.jsnpm | < 2.0.3 | 2.0.3 |
Affected products
2- Range: 0.0.1, 0.0.2, 0.2.0, …
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.