Description
gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number signs, and uses each segment as a dynamic object key without rejecting __proto__, constructor, or prototype. When an application converts untrusted PO or i18next translation data, a __proto__ segment resolves Object.prototype as the nested write target and Object.assign writes attacker-controlled translated properties onto the process-wide prototype. The resulting prototype pollution can cause denial of service and may enable application-dependent follow-on attacks. This issue is fixed in version 1.3.3.
Published: 2026-09-14
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Prototype Pollution and Denial of Service
Action: Apply Patch
AI Analysis

Impact

gettext-converter’s js2i18next() routine splits nested translation keys using options.keyseparator, whose default value is the two number signs "##", and assigns each segment as a dynamic object key without filtering reserved segments like __proto__, constructor, or prototype. When the tool processes untrusted PO or i18next translation data that includes a __proto__ segment, Object.assign writes attacker‑controlled translated properties onto Object.prototype, polluting the process‑wide JavaScript prototype. This prototype pollution can lead to denial of service and may enable application‑dependent follow‑on attacks. The flaw was remedied in version 1.3.3.

Affected Systems

All releases of the locize gettext-converter package earlier than version 1.3.3 are affected. The vulnerability is triggered when the js2i18next() utility processes PO or i18next translation data supplied by an attacker.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.3, indicating a high severity. The EPSS score is < 1%, indicating a very low likelihood of exploitation, yet the CVSS remains high. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by injecting crafted translation keys into PO or i18next files that the conversion tool consumes; the attack is local to the environment where the tool runs, but the impact may propagate to any application that loads polluted prototypes. Given the low EPSS score, real‑world exploitation is currently unlikely, but the high CVSS score warrants timely remediation.

Generated by OpenCVE AI on September 20, 2026 at 23:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to gettext-converter v1.3.3 or newer, which removes the prototype pollution flaw
  • If immediate upgrade is not possible, validate and sanitize all translation keys before passing them to js2i18next by rejecting any key containing "__proto__", "constructor", or "prototype" fragments
  • For applications that must process external translation files, restrict access to trusted sources only or run the conversion in a sandboxed environment to prevent unintended prototype modification
  • After remediation, monitor applications for signs of prototype mutation or unexpected global behavior

Generated by OpenCVE AI on September 20, 2026 at 23:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f4jp-rw7w-ccwg gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Locize
Locize gettext-converter
Vendors & Products Locize
Locize gettext-converter

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-915
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Important


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number signs, and uses each segment as a dynamic object key without rejecting __proto__, constructor, or prototype. When an application converts untrusted PO or i18next translation data, a __proto__ segment resolves Object.prototype as the nested write target and Object.assign writes attacker-controlled translated properties onto the process-wide prototype. The resulting prototype pollution can cause denial of service and may enable application-dependent follow-on attacks. This issue is fixed in version 1.3.3.
Title gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
Weaknesses CWE-1321
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Locize Gettext-converter
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:53:39.960Z

Reserved: 2026-06-16T21:59:57.018Z

Link: CVE-2026-55451

cve-icon Vulnrichment

Updated: 2026-09-14T18:53:15.089Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T17:17:48.383

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-55451

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T16:49:36Z

Links: CVE-2026-55451 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes