Executive brief
The GTranslate module for Drupal, which provides language translation widgets, contains a security flaw that could allow an attacker to manipulate website links. By injecting specific HTML, an attacker could redirect users to malicious domains when they attempt to use the language switcher. This risk is primarily limited to sites where attackers have the ability to post custom HTML and those using the paid version of the GTranslate service.
Technical details
A vulnerability exists in the GTranslate module's widget JavaScript due to insufficient validation of the 'document.currentScript' element. This allows for DOM clobbering or link manipulation where an attacker capable of injecting HTML with specific attributes can override script-provided values. Consequently, the generated language-switcher links can be forced to point to an unintended or malicious domain. The attack requires the ability to bypass default CKEditor configurations to inject restricted HTML attributes and is specifically applicable to configurations using the paid version of the GTranslate widget. The issue is resolved in version 3.0.5.
Affected products
- Drupal Translate Drupal with GTranslate 0.0.0 before 3.0.5
Timeline
- 2026-05-13: advisory: Drupal security advisory SA-CONTRIB-2026-035 published
- 2026-05-19: disclosed: CVE-2026-8492 published to NVD
- 2026-05-13: patched: Version 3.0.5 released to address the vulnerability