mediumCVSS 4.7Vulnerability

GHSA-6457-mxpq-4fqq

### Summary Versions of `i18nextify` prior to 4.0.8 substitute `{{key}}` interpolation tokens inside `src` and `href` attribute values with the raw string returned by `i18next.t()`. The substitution logic in `src/localize.js` (`replaceInside` handler around line 122) only guards against a duplicated `http://` origin prefix — it does not validate the URL scheme of the substituted value. A translated value such as `javascript:alert(1)` or `data:text/html,<script>...</script>` is applied unchanged to the live DOM attribute. ### Impact When an attacker can influence the content of a translation file or the translation-backend response — compromised translation CDN, user-contributed locales, MITM on a plain-HTTP backend, write access to the translation JSON — they can: - Set any `href` on an anchor to a `javascript:` URI, executing arbitrary JavaScript when the victim clicks the link. - Set any `src` on `<iframe>`, `<object>`, or `<embed>` to a `data:text/html` URI containing a full script payload that runs in the page's origin. - Use `vbscript:` on legacy IE installations or `file:` for local-resource navigation attacks. This path is distinct from the general i18nextify design that intentionally renders HTML from translations — href/src schemes are narrow and attack-specific, and no legitimate translation needs `javascript:` or `data:`. The fix therefore blocks these schemes outright without changing other behaviour. ### Also fixed in 4.0.8 - **`debug` / `saveMissing` URL-parameter substring match.** The previous detection `window.location.search.indexOf('debug=true') > -1` matched the substring anywhere in the query string. A URL like `?nosaveMissing=true` silently enabled `saveMissing` mode, causing the victim's browser to POST every unknown translation key to the configured `addPath` — a form of CSRF-style abuse of missing-key reporting. `?track_debug=true` enabled verbose debug logging, leaking i18next internals to the console. Now uses `URLSearchParams` for

Properties

ghsa_id
GHSA-6457-mxpq-4fqq
severity
medium
summary
i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes
cvss_score
4.7
cve_id
GHSA-6457-mxpq-4fqq
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-04-22T17:42:24Z
source_url
https://github.com/advisories/GHSA-6457-mxpq-4fqq
ghsa_updated
2026-04-22T17:42:25Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/i18nextify

AFFECTS (1)

[Software]npm/i18nextify

HAS_WEAKNESS (2)

[Weakness]Improper Control of Generation of Code ('Code Injection')
[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph