Prototype pollution in i18next-fs-backend - CVE-2026-48713
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript code.
The vulnerability exists due to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in information disclosure or data manipulation.
Affected software
DataStage on Cloud Pak for Data
How to mitigate CVE-2026-48713
DataStage on Cloud Pak for Data - addressed in versions 5.3.1 patch 10, 5.4 patch 5