gettext-converter is vulnerable to Prototype Pollution
58
Medium Risk
js2i18next() was vulnerable to prototype pollution when translation keys included dangerous segments like __proto__, constructor, or prototype. An attacker could craft translation keys that modified Object.prototype during JSON generation. The fix adds explicit detection of these unsafe key segments and skips/removes them so they cannot be used as dynamic object keys.
You are affected if you are using a version that falls within the vulnerable range.
gettext-converter is vulnerable to Prototype Pollution in versions 0.0.1 - 1.3.2.
Upgrade the gettext-converter library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant