CVE-2024-21528 Information
Sep 11, 2024
cve
Description
All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.
Reference
https://security.snyk.io/vuln/SNYK-JS-NODEGETTEXT-6100943 https://github.com/alexanderwallin/node-gettext/blob/65d9670f691c2eeca40dce129c95bcf8b613d344/lib/gettext.js%23L113
Share on: