i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This vulnerability affects i18next 2.0.0 and later.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2018-05-29T20:00:00Z

Updated: 2024-09-16T18:38:55.446Z

Reserved: 2017-10-29T00:00:00

Link: CVE-2017-16010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-29T20:29:02.190

Modified: 2024-11-21T03:15:39.640

Link: CVE-2017-16010

cve-icon Redhat

No data.