Modification of assumed-immutable data in Translate Drupal with GTranslate - CVE-2026-8492
Published: May 26, 2026
Translate Drupal with GTranslate
Detailed vulnerability description
The vulnerability allows a remote user to bypass certain security restrictions.
The vulnerability exists due to the affected widget JavaScript does not sufficiently validate that document.currentScript referred to the executing script element. A remote administrator can cause the generated language-switcher links to point to an unintended domain.