CVE-2025-53892Patch

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails to prevent execution of certain tag-based payloads, such as <img src=x onerror=...>, if the interpolated value is inserted inside an HTML context using v-html. This may lead to a DOM-based XSS vulnerability, even when using escapeParameterHtml: true, if a translation string includes minor HTML and is rendered via v-html. Versions 9.14.5, 10.0.8, and 11.1.0 contain a fix for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-17: 1Patch / Workaround · 2026-05-17: 105-17
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • kazupon@kazupon
    Patch

    vue-i18n master の PR #2470 をrevertした。CVE-2025-53892 backportでコード自体に悪意があるコードは無いんだけど、contributorのGitHubアカウントがrename→ 削除っていう感じでsupply chain attackの前兆パターンっぽいので未知のケースの可能性もあるから念のため。ここ昨今のOSS界隈怖すぎる... 修正は自分で再適用します。 https://github.com/intlify/vue-i18n/pull/2485

    Post summary

    The author notes a revert of a backported CVE‑2025‑53892, expresses concern about a potential supply‑chain hint, and states that they will reapply the fix via a new pull request.

    12941894891.9K
    6.8K followersView on X

Explore more