DOM-Based XSS Vulnerability in TripleLift Ad Rendering Script
CVE-2026-82019

2.3LOW

Key Information:

Vendor

Triplelift

Vendor
CVE Published:
14 September 2026

What is CVE-2026-82019?

TripleLift's ad rendering script, video-bundle.js, contains a DOM-based cross-site scripting vulnerability. This flaw allows unauthenticated attackers to execute arbitrary JavaScript within a publisher's domain by sending specially crafted postMessage payloads that lack origin validation. An attacker can lure victims to their controlled pages, which send malicious postMessage events to a publisher page running the vulnerable ad script. This exploitation could lead to session hijacking and unauthorized manipulation of the Document Object Model (DOM).

Affected Version(s)

video-bundle.js 0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hussein-Mahmoud7
.