Description
i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This vulnerability affects i18next 2.0.0 and later.
Remediation
References
https://github.com/i18next/i18next/pull/826
https://nodesecurity.io/advisories/326
Related Vulnerabilities
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.sonos
CVE-2021-29442 Vulnerability in maven package com.alibaba.nacos:nacos-common
CVE-2021-21344 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-23622 Vulnerability in maven package org.fourthline.cling:cling-core
CVE-2018-20677 Vulnerability in maven package org.fujion.webjars:bootstrap