Vulnerability in Accessible Cookie Banner from AmauriC
CVE-2025-48939

4.2MEDIUM

Key Information:

Vendor

Amauric

Vendor
CVE Published:
3 July 2025

What is CVE-2025-48939?

A vulnerability has been discovered in the tarteaucitron.js cookie banner library, prior to version 1.22.0. This issue arises from improper handling of the document.currentScript property, which may lead to unintended behavior or script loading failures. If an attacker successfully injects an HTML element, they can manipulate the resolution of document.currentScript, potentially allowing them to alter the CDN domain for the library. This vulnerability highlights the need for strict validation of script elements. Users are urged to upgrade to version 1.22.0 or later to mitigate this risk.

Affected Version(s)

tarteaucitron.js < 1.22.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48939 : Vulnerability in Accessible Cookie Banner from AmauriC