Y18n Project maintains a lightweight internationalization library used to embed string localization in JavaScript and Node.js applications, with its vulnerability footprint concentrating narrowly around the y18n product itself. Observed weakness classes center on prototype pollution—improper modification of object prototype attributes—a class endemic to JavaScript's dynamic object model that can lead to unexpected behavior or code execution when untrusted data flows into object property assignment.
The number and severity of CVEs published that impact products developed by Y18n Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7774CRITICAL The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution. | Nov 17, 2020 | 9.8 | 70 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Y18n Project.
Media articles that mention a CVE ID that affects a product developed by Y18n Project — matched by CVE ID, not by vendor name.