Vulnerability library
Security checkJuly 17, 2025

vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - vue-i18n

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmvue-i18n

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, this setting fails to prevent execution of certain tag-based payloads, such as <img src=x onerror=...>, if the interpolated value is inserted inside an HTML context using v-html.

Recommendation

Update the vue-i18n package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 11.0.0, < 11.1.10 >= 10.0.0, < 10.0.8 >= 9.0.0, < 9.14.5**
  • Patched version(s): **11.1.10 10.0.8 9.14.5**

References

Could your website be exposed too?

SmartScanner can check your website for vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - vue-i18n and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 17, 2025