Search/CVE-2025-48939
CVE — Medium

CVE-2025-48939

tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual element. If an attacker injected an HTML element, it could clobber the document.currentScript property. This causes the script to resolve incorrectly to an element instead of the tag, leading to unexpected behavior or failure to load the script path correctly. This issue arises because in some browser environments, named DOM elements become properties on the global document object. An attacker with control over the HTML could exploit this to change the CDN domain of tarteaucitron. This issue has been patched in version 1.22.0.

CVSS v3.1
4.2 MEDIUM
EPSS
0.18%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredHIGH
User InteractionREQUIRED
ScopeCHANGED
ConfidentialityNONE
IntegrityLOW
AvailabilityLOW
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:L
Connections
2 relationships
Timeline
disclosure → media coverage
Jul 3, 2025
Disclosure — published as a CVE record. · last revised by NVD Oct 21, 2025