Vulnerability library
Security checkMarch 10, 2025

Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/vue-i18n-core

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Vulnerability type: Prototype Pollution

Vulnerability Location(s):

Description:

The latest version of @intlify/message-resolver (9.1) and @intlify/vue-i18n-core (9.2 or later), (previous versions might also affected), is vulnerable to Prototype Pollution through the entry function(s) handleFlatJson.

Recommendation

Update the @intlify/vue-i18n-core package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 11.0.0-beta.0, < 11.1.2 >= 10.0.0-alpha.1, < 10.0.6 >= 9.2.0, < 9.14.3**
  • Patched version(s): **11.1.2 9.14.3**

References

Could your website be exposed too?

SmartScanner can check your website for Vue I18n Allows Prototype Pollution in `handleFlatJson` - @intlify/vue-i18n-core and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 10, 2025