Crypto-Related Vulnerability in Prebid Universal Creative by Prebid
CVE-2025-59039
9.3CRITICAL
What is CVE-2025-59039?
Prebid Universal Creative (PUC) has exposed npm users of version 1.17.3 and the latest releases to a crypto-related malware threat. The vulnerability arose due to the use of compromised code hosted on the popular jsdelivr platform. In response, PUC maintainers unpublished version 1.17.3, advising users to transition to version 1.17.2 or consult the Prebid.js 9 release notes for guidance on discontinuing the deprecated workflow associated with PUC. Immediate action is recommended for those currently leveraging these versions to mitigate the risk of future attacks.
Affected Version(s)
prebid-universal-creative = 1.17.3