CVE-2026-41693General

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18next-fs-backend substitutes the lng and ns options directly into the configured loadPath / addPath templates and then read / write the resulting file from disk. The interpolation is unencoded and unvalidated, so a crafted lng or ns value — containing .., a path separator, a control character, a prototype key, or simply an unexpectedly long string — allows an attacker who can influence either value to read or overwrite files outside the intended locale directory. When lng / ns are derived from untrusted input (request-scoped i18next instances behind an HTTP layer such as i18next-http-middleware, or any framework that lets the end user pick the language via query string, cookie, or header), a single request such as ?lng=../../../../etc/passwd causes the backend to attempt to read that path. This issue has been patched in version 2.6.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-08: 2Technical Details · 2026-05-08: 105-08
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41693 Path Traversal Vulnerability in i18next-fs-backend Prior to Version 2.6.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41693

    Post summary

    The post identifies a path traversal issue in i18next‑fs‑backend before v2.6.4 and references CVE‑2026‑41693, but it offers no PoC, exploit, active‑use claims, or workaround.

    0000040
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41693 i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem. Prior to version 2.6.4, i18next-fs-backend s… https://www.cve.org/CVERecord?id=CVE-2026-41693

    Post summary

    The snippet references CVE-2026-41693 for i18next-fs-backend, noting its affected version but providing no detailed vulnerability, exploit, or mitigation information.

    0000056
    57.5K followersView on X

Explore more