Skip to main content

Threats Tagged 'ghsa-xvq9-wjp8-hwqf'

View all threats tagged with 'ghsa-xvq9-wjp8-hwqf'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: ghsa-xvq9-wjp8-hwqf

Threats Tagged 'ghsa-xvq9-wjp8-hwqf'

Click on any threat for detailed analysis and mitigation recommendations

There is an SSRF vulnerability when using `i18next-http-backend`. A colon in an attacker-controlled language value can make a custom path template request an unintended origin. This is reachable under the following conditions: Attacker controls i18next language or namespace input that is interpolated into loadPath. ## Proof of Concept ```js // SSRF through a colon-only URL scheme in i18next-http-backend interpolation. const http = require("node:http"); const Backend = require("i18next-http-backend"); function read(backend, lng, ns) { return new Promise((resolve) => { backend.read(lng, ns, (err) => resolve(err)); }); } async function main() { let gotRequest = false; const server = http.createServer((req, res) => { gotRequest = req.url === "/common.json"; res.writeHead(200, { "content-type": "application/json" }); res.end("{}"); }); await new Promise((resolve) => server.listen(0, "127.0.0.1", resolve)); const backend = new Backend(null, { loadPath: "{{lng}}/{{ns}}.json" }); const lng = `http:127.0.0.1:${server.address().port}`; const err = await read(backend, lng, "common"); server.close(); const vulnerable = gotRequest && !err; console.log(vulnerable ? "VULNERABLE" : "SAFE"); if (!vulnerable) process.exitCode = 1; } main(); ``` Run: ```bash npm install --ignore-scripts node poc.js ``` The expected result is: ```text VULNERABLE ``` ## Why the Previous Patch Was Incomplete This vulnerability is caused by an incomplete patch for [CVE-2026-41691](https://github.com/advisories/GHSA-q89c-q3h5-w34g). The previous patch addressed the following behavior: Original hardening blocks path traversal and selected URL-control characters in lng/ns. The following bypass remains in the current release: lng=http:127.0.0.1:<port> with loadPath={{lng}}/{{ns}}.json; colon is not blocked and produces an outbound request. ## Impact The attacker-controlled language or namespace value can redirect the backend request to an unintended origin, resulting in URL injection and possible SSRF. ## Recommended Fix Parse the final URL and require it to remain within the intended origin and path. If absolute URLs are supported, validate them against an explicit allowlist. Please let us know if you need any additional information or clarification. We are happy to prepare a pull request if that would be helpful. Thank you for reviewing this report. ## Maintainer note Confirmed and fixed in 4.0.2 (commit i18next/i18next-http-backend@07e0288). **Preconditions.** The bypass only works when the `loadPath` / `addPath` template *begins* directly with `{{lng}}` or `{{ns}}` — no origin and no leading `/`, e.g. `{{lng}}/{{ns}}.json`. Only in that position is `http:` parsed as a URL scheme. The default `/locales/{{lng}}/{{ns}}.json` and every template with a leading path or origin are **not** affected: a colon inside a path segment has no structural meaning there, and the resulting string is rejected as an invalid URL. The same template shape also allowed an `ns` value such as `//evil.example/x` to become a protocol-relative URL in browsers. **Fix.** `:` is now rejected in both `lng` and `ns` values, and `//` in `ns` values. No BCP-47 language code contains a colon, and `:` is i18next's default namespace separator, so no usable namespace name does either. **Affected range.** Versions before 3.0.5 had no validation at all and are reachable through this vector too, so the affected range is `< 4.0.2` rather than `>= 3.0.5, <= 4.0.1`.

Join the discussion

Showing 1 to 1 of 1 result

Filters:Tag: ghsa-xvq9-wjp8-hwqf
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses