Feed/CVE-2026-55451
CVE-2026-55451MEDIUMCVSS 0.0

gettext-converter: Prototype pollution in js2i18next() via crafted translation keys

Published Aug 20, 2026·Updated Aug 20, 2026

NVD Description

### Impact `js2i18next()` is vulnerable to prototype pollution. When converting translations, it splits nested keys on the key separator (default `##`) and uses each segment as a dynamic object key while building the output object. A key whose segment is `__proto__` (e.g. `__proto__##gcPolluted`) causes the converter to resolve `Object.prototype` as the nested write target and assign the translated value onto it, polluting `Object.prototype` for the whole runtime. Any application that converts translation data (PO / i18next JS objects) originating from an untrusted or user-controlled source is affected. Prototype pollution can lead to denial of service and, depending on the surrounding application, may enable further attacks. ### Patches Fixed in `gettext-converter@1.3.3`. Key segments equal to `__proto__`, `constructor`, or `prototype` are now rejected before being used as dynamic object keys. ### Workarounds Upgrade to `1.3.3`. If upgrading is not immediately possible, sanitize/validate translation keys before passing them to `js2i18next()` and reject any key whose `##`-separated segments include `__proto__`, `constructor`, or `prototype`.

Affected Packages (1)

gettext-converterNPM
Fixed in 1.3.3

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free