VYPR

npm package

gettext.js

pkg:npm/gettext.js

Vulnerabilities (1)

  • CVE-2024-43370HigAug 16, 2024
    affected < 2.0.3fixed 2.0.3

    gettext.js is a GNU gettext port for node and the browser. There is a cross-site scripting (XSS) injection if `.po` dictionary definition files are corrupted. This vulnerability has been patched in version 2.0.3. As a workaround, control the origin of the definition catalog to pr