Executive brief
i18next-http-middleware is a tool used by web applications to handle language translations. A security flaw in versions prior to 3.9.3 allows attackers to manipulate language and namespace parameters to access sensitive files on the server or make unauthorized requests to internal systems. This could lead to the theft of configuration files, credentials, or private data, potentially compromising the entire server environment.
Technical details
The vulnerability exists in the `getResourcesHandler` function of i18next-http-middleware. User-controlled `lng` (language) and `ns` (namespace) values are passed directly to `i18next.services.backendConnector.load()` without sanitization. If the middleware is used with `i18next-fs-backend`, an attacker can use path traversal sequences (e.g., `../../etc/passwd`) to read arbitrary files. If used with `i18next-http-backend`, an attacker can perform SSRF by reshaping the outgoing URL to target internal services. The issue is fixed in version 3.9.3 by implementing a safety check (`isSafeIdentifier`) that rejects relative path sequences, path separators, and control characters.
Affected products
- i18next i18next-http-middleware < 3.9.3
Timeline
- 2026-04-22: advisory: GitHub Security Advisory published
- 2026-05-08: disclosed: NVD publication date