Vulnerability in Accessible Cookie Banner from AmauriC
CVE-2025-48939
4.2MEDIUM
What is CVE-2025-48939?
A vulnerability has been discovered in the tarteaucitron.js cookie banner library, prior to version 1.22.0. This issue arises from improper handling of the document.currentScript property, which may lead to unintended behavior or script loading failures. If an attacker successfully injects an HTML element, they can manipulate the resolution of document.currentScript, potentially allowing them to alter the CDN domain for the library. This vulnerability highlights the need for strict validation of script elements. Users are urged to upgrade to version 1.22.0 or later to mitigate this risk.
Affected Version(s)
tarteaucitron.js < 1.22.0