CVE-2017-16010: i18next

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This vulnerability affects i18next 2.0.0 and later.

Affected products

  • i18next i18next: from 2.0.0, up to and including 3.4.3

Published 2018-05-29. Last modified 2026-06-17.