Two critical prototype pollution vulnerabilities, CVE-2026-48713 and CVE-2026-48714, were disclosed in the widely used Node.js internationalization components i18next-fs-backend and i18next-http-middleware. The bugs allow attacker-controlled missing translation keys to traverse unsafe path segments such as __proto__, constructor, and prototype, potentially writing arbitrary properties into Object.prototype. In affected deployments, successful exploitation can trigger application crashes, corrupt translation behavior, poison configuration, and bypass property-based security checks.
The primary backend flaw affects i18next-fs-backend versions before 2.6.6, while the middleware flaw affects i18next-http-middleware versions before 3.9.7 and can help remote input reach the vulnerable backend path by failing to block dotted payloads such as __proto__.polluted. Exploitation depends on applications exposing missingKeyHandler or similar saveMissing functionality to untrusted users with key splitting enabled. Maintainers patched the issues by blocking unsafe path traversal, and defenders are advised to upgrade immediately, restrict missing-key routes to trusted users, disable missing-key persistence for untrusted input, or set keySeparator to false where appropriate.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-48714 was disclosed as a critical prototype pollution vulnerability in i18next-http-middleware affecting versions before 3.9.7. The issue stems from missingKeyHandler rejecting literal unsafe keys but not dotted variants that can reach vulnerable backends.
CVE-2026-48713 was disclosed as a critical prototype pollution vulnerability in i18next-fs-backend affecting versions before 2.6.6. The flaw allows crafted missing-key strings from untrusted input to write arbitrary properties to Object.prototype under certain configurations.
Maintainers fixed CVE-2026-48714 in i18next-http-middleware version 3.9.7. The fix addressed missingKeyHandler failing to reject dotted prototype-polluting key variants such as "__proto__.polluted".
Maintainers fixed CVE-2026-48713 in i18next-fs-backend version 2.6.6 by blocking unsafe path traversal through prototype-polluting segments such as __proto__, constructor, and prototype.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.