Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f4jp-rw7w-ccwg | gettext-converter: Prototype pollution in js2i18next() via crafted translation keys |
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number signs, and uses each segment as a dynamic object key without rejecting __proto__, constructor, or prototype. When an application converts untrusted PO or i18next translation data, a __proto__ segment resolves Object.prototype as the nested write target and Object.assign writes attacker-controlled translated properties onto the process-wide prototype. The resulting prototype pollution can cause denial of service and may enable application-dependent follow-on attacks. This issue is fixed in version 1.3.3. | |
| Title | gettext-converter: Prototype pollution in js2i18next() via crafted translation keys | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-14T18:53:39.960Z
Reserved: 2026-06-16T21:59:57.018Z
Link: CVE-2026-55451
Updated: 2026-09-14T18:53:15.089Z
Status : Received
Published: 2026-09-14T17:17:48.383
Modified: 2026-09-14T19:17:32.213
Link: CVE-2026-55451
No data.
OpenCVE Enrichment
No data.
Github GHSA