Junglewise Threat Intelligence

CVE-2026-41885: locize i18next-locize-backend path traversal and URL injection

CVE-2026-41885 · Severity: medium · CVSS 6.5 · Published 2026-05-08

Vendors: npm.

Executive brief

i18next-locize-backend is a library used to connect applications to the locize translation management service. A vulnerability in how it handles user-provided data allows attackers to manipulate the web addresses (URLs) the application uses to fetch content. This could lead to the application displaying incorrect or malicious content, or in some server-side configurations, allow an attacker to access sensitive internal files or perform unauthorized network requests.

Technical details

The i18next-locize-backend library fails to validate or encode parameters such as 'lng', 'ns', 'projectId', and 'version' before interpolating them into URL templates (e.g., loadPath, privatePath). An attacker can provide crafted input via query parameters, cookies, or headers to perform path traversal (e.g., using '../../'), query-string injection, or fragment truncation. This can result in the application loading unintended translation resources. In server-side environments with custom loadPath configurations, this may escalate to Server-Side Request Forgery (SSRF) or arbitrary file read. Additionally, the pre-patch interpolation helper was susceptible to prototype pollution amplification. The issue is fixed in version 9.0.2 by implementing strict URL segment validation and encoding.

Affected products

  • locize i18next-locize-backend < 9.0.2

Timeline

  • 2026-04-18: advisory: GitHub Security Advisory published by the maintainer
  • 2026-05-08: disclosed: CVE-2026-41885 published to NVD
  • 2026-05-08: patched: Version 9.0.2 released to address the vulnerability

References