Junglewise Threat Intelligence

CVE-2026-49977: AmauriC tarteaucitron.js unauthorized cookie deletion via data-cookie attribute

CVE-2026-49977 · Severity: medium · CVSS 4.3 · Published 2026-07-17

Technologies: AmauriC Tarteaucitron.Js, tarteaucitronjs (npm). Vendors: AmauriC, Drupal, npm.

Executive brief

tarteaucitron.js is a popular tool used by websites to manage cookie consent and comply with privacy laws. A security flaw allows an attacker who can post content on a site (such as in a comment or profile) to create a hidden trigger that deletes a visitor's cookies when they click a specific link. This could be used to disrupt user sessions or clear preferences, though it cannot be used to steal sensitive data protected by standard browser security settings.

Technical details

An improper authorization vulnerability (CWE-285) exists in tarteaucitron.js due to insufficient validation in the cookie purging mechanism. The `tarteaucitron.cookie.purge()` function is triggered by any HTML element assigned the `purgeBtn` class without verifying if the element is a legitimate part of the library's UI. If an attacker can inject HTML with data attributes (e.g., via a CMS or comment section), they can use the `data-cookie` attribute to specify a cookie name for deletion. When a user clicks the malicious element, the specified non-HttpOnly cookie is deleted. This issue is fixed in tarteaucitron.js version 1.33.0 and Drupal TacJS version 8.x-6.8.

Affected products

  • AmauriC tarteaucitron.js < 1.33.0
  • Drupal TacJS < 8.x-6.8

Timeline

  • 2026-05-27: patched: tarteaucitron.js version 1.33.0 released
  • 2026-06-03: advisory: GitHub Security Advisory and Drupal SA-CONTRIB-2026-040 published
  • 2026-07-17: disclosed: CVE-2026-49977 published to NVD

References

Related threats