{"id":"GHSA-6457-mxpq-4fqq","summary":"i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes","details":"### Summary\n\nVersions of `i18nextify` prior to 4.0.8 substitute `{{key}}` interpolation tokens inside `src` and `href` attribute values with the raw string returned by `i18next.t()`. The substitution logic in `src/localize.js` (`replaceInside` handler around line 122) only guards against a duplicated `http://` origin prefix — it does not validate the URL scheme of the substituted value. A translated value such as `javascript:alert(1)` or `data:text/html,\u003cscript\u003e...\u003c/script\u003e` is applied unchanged to the live DOM attribute.\n\n### Impact\n\nWhen an attacker can influence the content of a translation file or the translation-backend response — compromised translation CDN, user-contributed locales, MITM on a plain-HTTP backend, write access to the translation JSON — they can:\n\n- Set any `href` on an anchor to a `javascript:` URI, executing arbitrary JavaScript when the victim clicks the link.\n- Set any `src` on `\u003ciframe\u003e`, `\u003cobject\u003e`, or `\u003cembed\u003e` to a `data:text/html` URI containing a full script payload that runs in the page's origin.\n- Use `vbscript:` on legacy IE installations or `file:` for local-resource navigation attacks.\n\nThis path is distinct from the general i18nextify design that intentionally renders HTML from translations — href/src schemes are narrow and attack-specific, and no legitimate translation needs `javascript:` or `data:`. The fix therefore blocks these schemes outright without changing other behaviour.\n\n### Also fixed in 4.0.8\n\n- **`debug` / `saveMissing` URL-parameter substring match.** The previous detection `window.location.search.indexOf('debug=true') \u003e -1` matched the substring anywhere in the query string. A URL like `?nosaveMissing=true` silently enabled `saveMissing` mode, causing the victim's browser to POST every unknown translation key to the configured `addPath` — a form of CSRF-style abuse of missing-key reporting. `?track_debug=true` enabled verbose debug logging, leaking i18next internals to the console. Now uses `URLSearchParams` for exact parameter matching.\n- **Optional `sanitize(html, ctx)` hook.** The library's core purpose is to render HTML from translations — a behaviour that is safe only when the translation source is fully trusted. Applications with partially-trusted sources (user-contributed locales, third-party CDN, MITM-exposed HTTP backend) can now wire a sanitizer (e.g. DOMPurify) via `i18next.options.sanitize`. Defaults to pass-through to preserve existing behaviour for the main use case.\n\n### Affected versions\n\nAll versions of `i18nextify` prior to **4.0.8**.\n\n### Patch\n\nFixed in **4.0.8**. The URL-scheme blocklist is `^\\s*(javascript|data|vbscript|file)\\s*:` (case-insensitive) applied to each translated value before it is joined back into the `href`/`src` attribute. Values matching the blocklist are replaced with an empty string so the attribute becomes harmless rather than leaving the attacker's URL in place.\n\n### Workarounds\n\nNo workaround short of upgrading. If you cannot upgrade immediately, audit every translation file for `javascript:`, `data:`, `vbscript:`, and `file:` prefixes in any value that may reach an `href`/`src` position, and restrict translation-file write access to trusted operators. Serving translations over HTTPS and pinning the translation backend to an internal origin reduce the MITM surface.\n\n### Credits\n\nDiscovered via an internal security audit of the i18next ecosystem.","aliases":["CVE-2026-41692"],"modified":"2026-05-11T13:53:13.645066Z","published":"2026-04-22T17:42:24Z","database_specific":{"github_reviewed_at":"2026-04-22T17:42:24Z","nvd_published_at":"2026-05-07T21:16:29Z","cwe_ids":["CWE-79","CWE-94"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/i18next/i18nextify/security/advisories/GHSA-6457-mxpq-4fqq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41692"},{"type":"WEB","url":"https://github.com/i18next/i18nextify/commit/16f23dbcdcf893673587f7a03355bf7ce0a0e49e"},{"type":"PACKAGE","url":"https://github.com/i18next/i18nextify"}],"affected":[{"package":{"name":"i18nextify","ecosystem":"npm","purl":"pkg:npm/i18nextify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.0.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-6457-mxpq-4fqq/GHSA-6457-mxpq-4fqq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}