Executive brief
next-intl is a JavaScript internationalization library for Next.js that manages translation catalogs and message formatting. When the experimental message precompilation feature is enabled, an attacker who controls translation files can inject malicious keys that pollute the JavaScript Object.prototype during the build process. This allows an attacker to tamper with generated web bundles and potentially alter application behavior during deployment, particularly when translation files are sourced from external translation management systems or community contributions.
Technical details
This is a prototype pollution vulnerability (CWE-1321) in the setNestedProperty function in packages/next-intl/src/extractor/utils.tsx. The function walks a dotted key path (e.g., "__proto__.isAdmin") without blocking reserved keys, and uses the "in" operator for existence checks, which traverses the prototype chain. When a JSON translation catalog contains a top-level "__proto__" key, the JSON.parse() call creates it as an own property. The traverseMessages function then iterates over Object.keys() and emits "__proto__.isAdmin" as a message ID, which is subsequently passed to setNestedProperty. The vulnerable code assigns to Object.prototype, polluting the entire build process. This occurs at build time in the webpack/turbopack loader when experimental.messages.precompile is enabled. The attack requires opt-in configuration but is realistic because translation files are often round-tripped through third-party TMS systems (Crowdin, Lokalise, Transifex) or accepted via community PRs with minimal scrutiny. The recommended fix is to reject reserved keys (__proto__, constructor, prototype) and replace the "in" operator check with Object.prototype.hasOwnProperty.
Affected products
- amannn next-intl <= 4.9.1
Timeline
- 2026-05-06: disclosed: GHSA-4c35-wcg5-mm9h published
- 2026-04-27: patched: Version 4.9.2 patched; advisory published 2026-04-27 per GitHub, OSV shows 2026-05-06