CVE-2017-16010: i18next
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This vulnerability affects i18next 2.0.0 and later.
Affected products
- i18next i18next: from 2.0.0, up to and including 3.4.3
Published 2018-05-29. Last modified 2026-06-17.