CVE-2025-53892: Intlify Vue I18n's escapeParameterHtml does not prevent DOM-based XSS via tag attributes like onerror
Summary The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, this setting fails to prevent execution of certain tag-based payloads, such as <img src=x onerror=...>, if the interpolated value is inserted inside an HTML context using v-html.
This may lead to a DOM-based XSS vulnerability, even when using escapeParameterHtml: true, if a translation string includes minor HTML and is rendered via v-html.
Details
When escapeParameterHtml: true is enabled, it correctly escapes common injection points.
However, it does not sanitize entire attribute contexts, which can be used as XSS vectors via:
<img src=x onerror=alert(1)> PoC In your Vue I18n configuration:
const i18n = createI18n({ escapeParameterHtml: true, messages: { en: { vulnerable: 'Caution: <img src=x onerror="{payload}">' } } }); Use this interpolated payload:
const payload = '<script>alert("xss")</script>'; Render the translation using v-html (even not using v-html):
<p v-html="$t('vulnerable', { payload })"></p> Expected: escaped content should render as text, not execute.
Actual: script executes in some environments (or the payload is partially parsed as HTML).
Impact
This creates a DOM-based Cross-Site Scripting (XSS) vulnerability despite enabling a security option (escapeParameterHtml) .
Other sources
Vue I18n is the internationalization plugin for Vue.js. The escapeParameterHtml: true option in Vue I18n is designed to protect against HTML/script injection by escaping interpolated parameters. However, starting in version 9.0.0 and prior to versions 9.14.5, 10.0.8, and 11.1.0, this setting fails to prevent execution of certain tag-based payloads, such as <img src=x onerror=...>, if the interpolated value is inserted inside an HTML context using v-html. This may lead to a DOM-based XSS vulnerability, even when using escapeParameterHtml: true, if a translation string includes minor HTML and is rendered via v-html. Versions 9.14.5, 10.0.8, and 11.1.0 contain a fix for the issue.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53892?
CVE-2025-53892 has been assigned a medium severity rating due to potential risks of HTML/script injection.
How do I fix CVE-2025-53892?
To fix CVE-2025-53892, update Vue I18n to version 9.14.5, 10.0.8, or 11.1.0 or later.
What versions of Vue I18n are affected by CVE-2025-53892?
Versions of Vue I18n between 9.0.0 and 9.14.5, as well as 10.0.0 to 10.0.8, and 11.0.0 to 11.1.0 are affected by CVE-2025-53892.
What vulnerabilities does CVE-2025-53892 address?
CVE-2025-53892 addresses vulnerabilities related to HTML/script injection due to improper escaping of interpolated parameters.
Who can be impacted by CVE-2025-53892?
Developers using affected versions of Vue I18n for internationalization in Vue.js applications may be impacted by CVE-2025-53892.