Executive brief
i18nextify is a JavaScript library used to automatically translate website content into different languages. A security flaw allows an attacker who can control translation data (for example, by compromising a translation provider or intercepting network traffic) to inject malicious code into the website. This could lead to unauthorized actions being performed in a user's browser, such as stealing session information or redirecting users to malicious sites when they click links.
Technical details
i18nextify versions prior to 4.0.8 contain a DOM XSS vulnerability in the 'replaceInside' handler within 'src/localize.js'. The library substitutes {{key}} interpolation tokens into 'src' and 'href' attributes without validating the URL scheme of the translated string. If an attacker can influence the translation source (via a compromised CDN, MITM on plain-HTTP backends, or malicious user-contributed locales), they can inject 'javascript:', 'data:', or 'vbscript:' URIs. When these translated values are applied to the DOM, they can execute arbitrary JavaScript in the context of the victim's browser session. The issue is patched in version 4.0.8, which introduces a blocklist for dangerous URL schemes.
Affected products
- i18next i18nextify < 4.0.8
Timeline
- 2026-04-18: advisory: GitHub advisory published by maintainers
- 2026-05-07: disclosed: CVE-2026-41692 published
- 2026-05-07: patched: Version 4.0.8 released with security hardening