Loading HuntDB...

GHSA-g974-hxvm-x689

GitHub Security Advisory

node-gettext vulnerable to Prototype Pollution

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

Affected Packages

npm node-gettext
Affected versions: 0 (last affected: 3.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-g974-hxvm-x689
Published
September 10, 2024 6:30 AM
Last Modified
November 18, 2024 4:27 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
node-gettext
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.