vue-i18n
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting vue-i18npage 1 of 1
- CVE-2024-52809MEDIUMCVSS 5.3EG 0.0✓ Fixed in 10.0.52024-11-29
vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-si…
- CVE-2024-52810MEDIUMCVSS 6.9EG 0.0✓ Fixed in 10.0.52024-11-29
@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.proto…
- CVE-2025-27597NONECVSS 0.0EG 0.0✓ Fixed in 11.1.22025-03-07
Vue I18n is the internationalization plugin for Vue.js. @intlify/message-resolver and @intlify/vue-i18n-core are vulnerable to Prototype Pollution through the entry function: handleFlatJson. An attacker can supply a payload with Object.pro…
- CVE-2025-53892NONECVSS 0.0EG 0.0✓ Fixed in 11.1.102025-07-16
Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior…
Check whether vue-i18n is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for vue-i18n CVEs against the assets you own.
Start Free Scan →