Path Traversal Vulnerability in i18next-locize-backend by Locize
CVE-2026-41885
6.5MEDIUM
What is CVE-2026-41885?
The i18next-locize-backend library, utilized for internationalization, contains a vulnerability that allows user-controlled inputs to bypass path validation and encoding. Prior to version 9.0.2, this lack of validation on query parameters, cookies, and request headers can lead to crafted values that alter the outgoing request URL structure. Affected functions in the library expose this risk, potentially allowing attackers to manipulate URLs deliberately. This issue has been addressed and patched in version 9.0.2.
Affected Version(s)
i18next-locize-backend < 9.0.2
