{"id":"CVE-2017-16010","details":"i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This vulnerability affects i18next 2.0.0 and later.","aliases":["GHSA-cmh5-qc8w-xvcq"],"modified":"2026-07-08T15:10:46.569113Z","published":"2018-05-29T20:29:02.190Z","references":[{"type":"REPORT","url":"https://github.com/i18next/i18next/pull/826"},{"type":"EVIDENCE","url":"https://nodesecurity.io/advisories/326"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/i18next/i18next","events":[{"introduced":"70d5840ffa1a4f27f94ae19b45909ecf441d73ee"},{"last_affected":"dbf369399e7e3519d7996a2818cbeed89ec2f3f8"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:i18next:i18next:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"2.0.0"},{"last_affected":"3.4.3"}]}}],"versions":["v3.4.3","v3.4.2","v3.4.1","v3.4.0","v3.3.1","v3.3.0","v3.2.0","v3.1.0","v3.0.0","v2.5.1","v2.5.0","v2.4.1","v2.4.0","v2.3.5","v2.3.4","v2.3.3","v2.3.2","v2.3.1","v2.3.0","2.2.0","2.1.0","2.0.26","2.0.25","2.0.24","2.0.23","2.0.22","2.0.21","2.0.20","2.0.19","2.0.18","2.0.16","2.0.14","2.0.13","2.0.12","2.0.11","2.0.10","2.0.9","2.0.8","2.0.7","2.0.6","2.0.5","2.0.1","2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16010.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}