Executive brief
node-gettext is a JavaScript library used to translate content in web applications and Node.js services. A prototype pollution vulnerability in its addTranslations() function allows attackers to pollute the JavaScript object prototype, potentially causing denial of service or enabling other attacks through application-level impacts.
Technical details
node-gettext is vulnerable to prototype pollution in the addTranslations() function due to improper sanitization of user-supplied input (CWE-1321). The vulnerability affects all versions up to and including version 3.0.0. An attacker can craft malicious translation data that, when processed by addTranslations(), pollutes the JavaScript prototype chain. This is a network-accessible attack with no authentication required, though successful exploitation may require specific preconditions. The impact is primarily denial of service through application availability degradation. Patches or fixed versions should be available from the package maintainer.
Affected products
- node-gettext node-gettext up to 3.0.0
Timeline
- 2024-09-10: disclosed
- 2024-09-10: advisory: GHSA-g974-hxvm-x689 published