PT-2026-106757 · Npm · I18Next-Http-Backend
CVE-2026-105800
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
i18next-http-backend versions prior to 4.0.2
Description
An issue exists where attacker-controlled language or namespace values interpolated into a custom
loadPath or addPath can lead to URL injection or server-side request forgery (SSRF). This occurs when the path template begins directly with the {{lng}} or {{ns}} placeholders, allowing a colon-based input to be interpreted as an absolute URL or a double-slash namespace to become a protocol-relative URL in browsers. This allows the request to leave the intended origin and target an unintended destination. The default template /locales/{{lng}}/{{ns}}.json and templates with a leading path or origin are not affected.Recommendations
Update to version 4.0.2.
As a temporary workaround, avoid using
loadPath or addPath templates that begin directly with {{lng}} or {{ns}} placeholders.Exploit
Fix
Special Elements Injection
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
I18Next-Http-Backend