Drupal Translate with GTranslate Resource Location Spoofing Vulnerability

Vulnerability

A vulnerability allowing resource location spoofing has been identified in the Translate Drupal with GTranslate module, affecting versions prior to 3.0.5. This issue arises from the module's JavaScript not properly validating the 'document.currentScript' reference, which could enable a user to manipulate language-switcher links to point to an unintended domain. The vulnerability is limited to sites using the paid versions of the GTranslate widget JavaScript, in configurations where the generated language links rely on script-provided values.

Impact

Exploitation of this vulnerability could lead to DOM clobbering and unauthorized manipulation of link destinations, potentially causing users to be directed to malicious or unintended websites.

Remediation

Users of the GTranslate module version 3.0.x should upgrade to GTranslate 3.0.5.

Added: May 19, 2026, 11:18 PM
Updated: May 19, 2026, 11:18 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
0.2
exploitability
5.4
remediation
7.7
relevance
8.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.