Description
Affected versions of i18next may fail to sanitize user input when certain configuration options are used. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true.
Recommendation
Update the i18next package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.0.0, < 3.4.4
- Patched version(s): 3.4.4
References
Could your website be exposed too?
SmartScanner can check your website for Cross-Site Scripting in i18next - i18next and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-Site Scripting in i18next - CVE-2017-16008
- Cross-Site Scripting in sanitize-html - CVE-2017-16017
- Cross Site Scripting (XSS) in plotly.js - CVE-2017-1000006
- Cross-Site Scripting in html-janitor - CVE-2017-0931


