THREAT OPS › Threat News › [GHSA] GHSA-f4jp-rw7w-ccwg (medium) — gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
[GHSA] GHSA-f4jp-rw7w-ccwg (medium) — gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
GHSA-f4jp-rw7w-ccwg Severity: medium CVE: CVE-2026-55451
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys
### Impact
`js2i18next()` is vulnerable to prototype pollution. When converting translations, it splits nested keys on the key separator (default `##`) and uses each segment as a dynamic object key while building the output object. A key whose segment is `
Indicators of compromise
- CVE-2026-55451cve
Original source: https://github.com/advisories/GHSA-f4jp-rw7w-ccwg