Executive brief
The translate library, a popular Node.js package for language translation, contains a cache poisoning vulnerability in how it handles cache keys. An attacker can manipulate the cache identifier to inject malicious translations that subsequent users will receive instead of legitimate results, potentially spreading misinformation or corrupting application data.
Technical details
The vulnerability exists in the opt.id parameter of the translate function, which improperly validates user-supplied input used to construct cache keys. An attacker who controls the second variable (language/options object) passed to the translate function can set a crafted id value matching the cache key that would be generated for another user's request. This allows the attacker to poison the cache so that subsequent translation requests for different text return the attacker's injected results. The attack requires network access to the application but no authentication or user interaction. Patches were available starting with version 2.0.2 according to some sources, though OSV indicates version 3.0.0 as the fixed version.
Affected products
- Francisco Polo (translate) translate <2.0.2
Timeline
- 2024-03-22: disclosed
- 2024-03-22: patched: Fix available in version 2.0.2 or later