Vulnerabilities/

i18next-locize-backend has URL Injection via Unsanitized Path Parameters

Severity:
Medium

Description

Versions of i18next-locize-backend prior to 9.0.2 interpolate lng, ns, projectId, and version directly into the configured loadPath / privatePath / addPath / updatePath / getLanguagesPath URL templates with no path-component validation and no encoding.

Recommendation

Update the i18next-locize-backend package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
i18next-locize-backend
Anything's wrong? Let us know Last updated on May 13, 2026