Description
vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3455 | vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-9r9m-ffp6-9x4v | vue-i18n has cross-site scripting vulnerability with prototype pollution |
References
History
Mon, 02 Dec 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Intlify
Intlify vue-i18n |
|
| CPEs | cpe:2.3:a:intlify:vue-i18n:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Intlify
Intlify vue-i18n |
|
| Metrics |
ssvc
|
Fri, 29 Nov 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versions 9.14.2, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |
| Title | Cross-site Scripting vulnerability with prototype pollution in vue-i18n | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-02T22:24:19.591Z
Reserved: 2024-11-15T17:11:13.443Z
Link: CVE-2024-52809
Updated: 2024-12-02T22:24:12.342Z
Status : Deferred
Published: 2024-11-29T19:15:09.030
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52809
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA