CVE-2024-21528

Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

Published 2024-09-10. Last modified 2026-06-17.