Impact
gettext-converter’s js2i18next() routine splits nested translation keys using options.keyseparator, whose default value is the two number signs "##", and assigns each segment as a dynamic object key without filtering reserved segments like __proto__, constructor, or prototype. When the tool processes untrusted PO or i18next translation data that includes a __proto__ segment, Object.assign writes attacker‑controlled translated properties onto Object.prototype, polluting the process‑wide JavaScript prototype. This prototype pollution can lead to denial of service and may enable application‑dependent follow‑on attacks. The flaw was remedied in version 1.3.3.
Affected Systems
All releases of the locize gettext-converter package earlier than version 1.3.3 are affected. The vulnerability is triggered when the js2i18next() utility processes PO or i18next translation data supplied by an attacker.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.3, indicating a high severity. The EPSS score is < 1%, indicating a very low likelihood of exploitation, yet the CVSS remains high. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by injecting crafted translation keys into PO or i18next files that the conversion tool consumes; the attack is local to the environment where the tool runs, but the impact may propagate to any application that loads polluted prototypes. Given the low EPSS score, real‑world exploitation is currently unlikely, but the high CVSS score warrants timely remediation.
OpenCVE Enrichment
Github GHSA