Path Traversal Vulnerability in i18next-locize-backend by Locize
CVE-2026-41885

6.5MEDIUM

Key Information:

Vendor

Locize

Vendor
CVE Published:
8 May 2026

What is CVE-2026-41885?

The i18next-locize-backend library, utilized for internationalization, contains a vulnerability that allows user-controlled inputs to bypass path validation and encoding. Prior to version 9.0.2, this lack of validation on query parameters, cookies, and request headers can lead to crafted values that alter the outgoing request URL structure. Affected functions in the library expose this risk, potentially allowing attackers to manipulate URLs deliberately. This issue has been addressed and patched in version 9.0.2.

Affected Version(s)

i18next-locize-backend < 9.0.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.