THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f4jp-rw7w-ccwg (medium) — gettext-converter: Prototype pollution in js2i18next() via crafted translation keys

[GHSA] GHSA-f4jp-rw7w-ccwg (medium) — gettext-converter: Prototype pollution in js2i18next() via crafted translation keys

medgithub_advisoriesPublished 2026-08-20

GHSA-f4jp-rw7w-ccwg Severity: medium CVE: CVE-2026-55451

gettext-converter: Prototype pollution in js2i18next() via crafted translation keys

### Impact

`js2i18next()` is vulnerable to prototype pollution. When converting translations, it splits nested keys on the key separator (default `##`) and uses each segment as a dynamic object key while building the output object. A key whose segment is `

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f4jp-rw7w-ccwg