Executive brief
tarteaucitron.js is a popular JavaScript library for managing cookie consent and third-party scripts on websites. An attacker who can inject HTML elements into a page could trick the library into loading scripts from an incorrect domain, potentially redirecting traffic to malicious CDNs and compromising the integrity of all scripts loaded by the library on that page.
Technical details
The vulnerability is a DOM clobbering attack (CWE-138) where the library accesses document.currentScript without verifying it is an actual HTMLScriptElement. An attacker can inject a named HTML element (e.g., <img name="currentScript">) which clobbers the document.currentScript property in some browser environments. This causes the script to resolve incorrectly, potentially allowing the attacker to change the CDN domain from which scripts are loaded. The attack requires local or adjacent network access, high privileges, and user interaction. A patch was released in version 1.22.0 that validates document.currentScript is an HTMLScriptElement instance and safely falls back to the last script tag if not.
Affected products
- AmauriC tarteaucitron.js before 1.22.0
Timeline
- 2025-07-03: disclosed
- 2025-07-03: patched: Version 1.22.0 released with fix (commit 230a3b6)