CNNVD-202507-2230 Information

CNNVD ID

CNNVD-202507-2230

CVE-2025-53892

  • CNNVD Published: 2025-07-16

Description (Chinese)

vue-i18n是intlify开源的一个应用程序。 vue-i18n 9.0.0至9.14.5之前版本、10.0.8之前版本和11.1.0之前版本存在跨站脚本漏洞,该漏洞源于HTML上下文参数转义不足,可能导致DOM型跨站脚本攻击。

Description (English)

vue-i18n is an application of inflify open source. Vue-i18n 9.0.0 to 9.14.5 before, 10.0.8 before, and 11.1.0 before, there is a gap in the cross-site script, which stems from insufficient replicating of the context parameters of HTML, which may lead to a DOM-type cross-site script attack.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

Intrexx

Published

2025-07-16

Last Modified

2026-02-24

References

https://github.com/intlify/vue-i18n/commit/49f982443ab8fd94ecc427b265ce97d57df94d7e https://github.com/intlify/vue-i18n/commit/a47099619fb9b256e86341a8658ebe72e92ab099 https://github.com/intlify/vue-i18n/pull/2229 https://github.com/intlify/vue-i18n/pull/2230 https://github.com/intlify/vue-i18n/releases/tag/v10.0.8 https://github.com/intlify/vue-i18n/releases/tag/v11.1.10 https://github.com/intlify/vue-i18n/releases/tag/v9.14.5 https://github.com/intlify/vue-i18n/security/advisories/GHSA-x8qp-wqqm-57ph

Patch

https://github.com/intlify/vue-i18n/releases

Share on: