GHSA-2933-q333-qg83
CRITICALCVE-2026-48713i18next-fs-backend ≤ 2.6.5, when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input), is vulnerable to prototype pollution via crafted missing-key strings.
- Affected
- < 2.6.6
- Fixed in
- 2.6.6
- Weakness
- CWE-1321
- Published
- 2026-06-25
- Source
- github