Crypto-Related Vulnerability in Prebid Universal Creative by Prebid
CVE-2025-59039

9.3CRITICAL

Key Information:

Vendor

Prebid

Vendor
CVE Published:
9 September 2025

What is CVE-2025-59039?

Prebid Universal Creative (PUC) has exposed npm users of version 1.17.3 and the latest releases to a crypto-related malware threat. The vulnerability arose due to the use of compromised code hosted on the popular jsdelivr platform. In response, PUC maintainers unpublished version 1.17.3, advising users to transition to version 1.17.2 or consult the Prebid.js 9 release notes for guidance on discontinuing the deprecated workflow associated with PUC. Immediate action is recommended for those currently leveraging these versions to mitigate the risk of future attacks.

Affected Version(s)

prebid-universal-creative = 1.17.3

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59039 : Crypto-Related Vulnerability in Prebid Universal Creative by Prebid