Description
Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing.

This issue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5.
Published: 2026-05-19
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, an instance of Modification of Assumed-Immutable Data, allows the Translate Drupal with GTranslate module to perform DOM clobbering and link manipulation. An attacker may craft or inject content that changes the destination of a link or resource reference, causing the user to be redirected to a malicious site without knowledge of the abuse. This provides the attacker with the ability to silently redirect users, potentially leading to phishing or malware delivery. The root weakness is classified as CWE‑471, indicating unreliable use of a data source that was intended to be immutable.

Affected Systems

The flaw exists in the Drupal Translate Drupal with GTranslate module, versions starting at 0.0.0 up to, but excluding, 3.0.5. Users running any of these versions are vulnerable. The issue is specific to the Drupal ecosystem and does not affect other platforms.

Risk and Exploitability

The exploitation of this flaw requires the ability to influence the module’s output, typically by injecting crafted content into a page that uses Translate. Users must be able to view the affected page, which may be an implicit attack vector. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploits. Nevertheless, because the attack can be performed through normal page rendering, the theoretical risk is moderate: it could be carried out by a distant adversary with knowledge of a vulnerable site. Due to the lack of an EPSS score, organizations should treat the risk as uncertain but potentially exploitable.

Generated by OpenCVE AI on May 19, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest release of Translate Drupal with GTranslate, version 3.0.5 or later, which removes the DOM clobbering flaw
  • If an update is not feasible, disable or uninstall the Translate module to eliminate the attack surface
  • Implement monitoring for unexpected redirects or changes in link behavior, and review user reports for possible phishing incidents

Generated by OpenCVE AI on May 19, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 20 May 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 May 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal translate Drupal With Gtranslate
Vendors & Products Drupal
Drupal translate Drupal With Gtranslate

Tue, 19 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5.
Title Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035
Weaknesses CWE-471
References

Subscriptions

Drupal Translate Drupal With Gtranslate
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-05-20T16:35:56.415Z

Reserved: 2026-05-13T15:43:27.852Z

Link: CVE-2026-8492

cve-icon Vulnrichment

Updated: 2026-05-20T16:25:49.513Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-19T23:16:58.860

Modified: 2026-05-20T18:16:28.137

Link: CVE-2026-8492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-20T10:38:46Z

Weaknesses