SCA: security update for i18next-http-backend (GHSA-q89c-q3h5-w34g)

critical Tenable Cloud Security Plugin ID 440726

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds
website internationalization via a script tag, without source code changes. Versions prior to 3.0.5
interpolate the lng and ns values directly into the configured loadPath / addPath URL template without any
encoding, validation, or path sanitisation. When an application exposes the language-code selection to
user-controlled input (the default — i18next-browser-languagedetector reads ?lng= query params, cookies,
localStorage, and request headers), an attacker can inject characters that change the structure of the
outgoing request URL. This is a single URL-injection vulnerability. The attacker-controlled value is
neutralised before it is used as part of an output URL string; the attack shape covers both path traversal
and broader URL-structure injection — both are closed by the one interpolateUrl sanitisation fix. This
issue has been fixed in version 3.0.5. If users cannot upgrade immediately, they can work around the issue
by sanitising lng / ns before they reach i18next (strip .., /, \, ?, #, %, whitespace, and control
characters; cap the length). (CVE-2026-41691)

Solution

Update the i18next-http-backend library and its related packages to version 3.0.5 or later.

See Also

https://github.com/advisories/GHSA-q89c-q3h5-w34g

Plugin Details

Severity: Critical

ID: 440726

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 4/22/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.6

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2026-41691

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/22/2026

Vulnerability Publication Date: 4/22/2026

Reference Information

CVE: CVE-2026-41691