i18next is vulnerable to Code Injection
84
High Risk
Affected versions of this package are vulnerable to code injection due to unsafe behavior in the i18n.t function. When requested keys do not exist, the function can return JavaScript objects such as constructor, potentially allowing attackers to execute arbitrary code in certain scenarios.
You are affected if you are using a version that falls within the vulnerable range.
i18next is vulnerable to Code Injection in versions 17.0.2 - 24.1.1.
Upgrade the i18next library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant