HIGHnpm

Vue I18n Allows Prototype Pollution in `handleFlatJson`

Vue I18n Allows Prototype Pollution in `handleFlatJson`

CVE-2025-27597Published 1 year agoUpdated 1 week agoSource: OSV

Affected packages

  • @intlify/core
  • @intlify/core-base
  • @intlify/message-resolver
  • @intlify/vue-i18n-core
  • petite-vue-i18n
  • vue-i18n

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Vue I18n Allows Prototype Pollution in `handleFlatJson` | HackTribune