oM noM Security Feeds cve
vulnerability context

CVE-2026-48713

CVSS 9.1 CRITICALEPSS 34%CWE-1321OTX 8 pulses

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key string on the configured keySeparator (default .) before calling the internal setPath() walker. The walker (getLastOfPath in lib/utils.js) did not guard against unsafe segments, so a key like "__proto__.polluted" was split into ["__proto__", "polluted"] and walked straight into Object.prototype, allowing an attacker to write...

Published 2026-06-15 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
9.1 / CRITICAL
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS
34% percentile (score 0.0042)
CWE
CWE-1321
OTX pulses
8 total, 0 recent

source mentions 2

source consensus

  • Bluesky:@cyberhub.blog
  • GitHub Advisories
Want the 3-bullet summary of CVE-2026-48713, plus webhook alerts when KEV is updated? Pro is $10/mo.