Skip to content

node-gettext vulnerable to Prototype Pollution

Moderate severity GitHub Reviewed Published Sep 10, 2024 to the GitHub Advisory Database • Updated Sep 10, 2024

Package

npm node-gettext (npm)

Affected versions

<= 3.0.0

Patched versions

None

Description

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

References

Published by the National Vulnerability Database Sep 10, 2024
Published to the GitHub Advisory Database Sep 10, 2024
Reviewed Sep 10, 2024
Last updated Sep 10, 2024

Severity

Moderate

EPSS score

0.043%
(10th percentile)

Weaknesses

CVE ID

CVE-2024-21528

GHSA ID

GHSA-g974-hxvm-x689
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.