@intlify/core
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @intlify/corepage 1 of 1
- CVE-2024-52809MEDIUMCVSS 5.3EG 5.3fixed in 9.14.2 or 10.0.5, by version range2024-11-29
vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-si…
- CVE-2025-27597HIGHCVSS 8.9EG 8.9fixed in 9.1.112025-03-07
Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.pro…
- CVE-2025-53892MEDIUMCVSS 5.3EG 5.3fixed in 9.14.5, 10.0.8 or 11.1.10, by version range2025-07-16
Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior…
Check whether @intlify/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @intlify/core CVEs against the assets you own.
Book a Demo →