Vulnerability library
Security checkMay 11, 2026

i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmi18nextify

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Versions of i18nextify prior to 4.0.8 substitute `` interpolation tokens inside src and href attribute values with the raw string returned by i18next.t(). The substitution logic in src/localize.js (replaceInside handler around line 122) only guards against a duplicated http:// origin prefix — it does not validate the URL scheme of the substituted value.

Recommendation

Update the i18nextify package to the latest compatible version. Followings are version details:

  • Affected version(s): < 4.0.8
  • Patched version(s): 4.0.8

References

Could your website be exposed too?

SmartScanner can check your website for i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated May 11, 2026