I18next is a lightweight internationalization library widely embedded in client-side and server-side JavaScript applications, where its narrow product scope masks broad downstream exposure through supply-chain distribution. Vulnerabilities affecting the library recur in input-handling and code-generation contexts—cross-site scripting, code injection, path traversal, and injection-class flaws—that arise from the templating and configuration-parsing mechanisms central to its localization function; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by I18next over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48714CRITICAL i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked | Jun 15, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-48713CRITICAL Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's miss | Jun 15, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-41691CRITICAL Copilot said: i18nextify is a JavaScript library that adds
i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. | May 7, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-41692MEDIUM i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation to | May 7, 2026 | 4.7 | 21 | NO | NO |
CVE-2017-16010MEDIUM i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the ass | May 29, 2018 | 6.1 | 20 | NO | NO |
CVE-2017-16008MEDIUM i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use th | Jun 4, 2018 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by I18next.
Media articles that mention a CVE ID that affects a product developed by I18next — matched by CVE ID, not by vendor name.