Intel

AIKIDO-2025-10351

@nextcloud/l10n is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

48

Medium Risk

This Affects:

js@nextcloud/l10n
2.0.0 - 3.1.0
Fixed in 3.2.0

TL;DR

Affected versions of this package are vulnerable to prototype pollution in the registry::registerAppTranslations function, allowing attackers to modify object properties and potentially alter application behavior.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

@nextcloud/l10n is vulnerable to Prototype Pollution in versions 2.0.0 - 3.1.0.

How to fix this

Upgrade the @nextcloud/l10n library to the patch version.

Background Info