Executive brief
Vue I18n is a popular JavaScript library for internationalization in Vue applications, enabling dynamic translation of application content. A flaw in the escapeParameterHtml security feature fails to prevent cross-site scripting (XSS) attacks when malicious payloads are embedded in HTML tag attributes (like onerror handlers), allowing attackers to execute arbitrary JavaScript code and compromise user sessions or steal sensitive data.
Technical details
This is a DOM-based XSS vulnerability in vue-i18n's escapeParameterHtml option, which is intended to sanitize interpolated parameters against HTML injection. The vulnerability exists because the escaping mechanism does not properly sanitize HTML attribute contexts, specifically event handler attributes like onerror. An attacker can craft a translation string containing an HTML tag with a malicious event handler (e.g., <img src=x onerror="malicious code">) and use v-html directive to render it, bypassing the escapeParameterHtml protection. No special privileges or authentication is required; the attack only requires user interaction with rendering the translated content. Patches are available in vue-i18n 9.14.5, 10.0.8, 11.1.10 and related @intlify packages with the same version constraints.
Affected products
- Intlify vue-i18n 9.0.0–11.1.9
- Intlify @intlify/core 9.0.0–11.1.9
- Intlify @intlify/core-base 9.0.0–11.1.9
- Intlify @intlify/vue-i18n-core 9.2.0–11.1.9
- Intlify petite-vue-i18n 10.0.0–11.1.9
Timeline
- 2025-07-16: disclosed: GHSA-x8qp-wqqm-57ph and CVE-2025-53892 published
- 2025-07-16: patched: Patches released: vue-i18n 9.14.5, 10.0.8, 11.1.10 and related @intlify packages