Junglewise Threat Intelligence

DRUPAL-CONTRIB-2026-040 - This module enables sites to comply with the European cookie law using tarteaucitron.js. The module doesn't sufficiently filter user-suppli

Severity: info · Published 2026-06-03

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Tacjs. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module enables sites to comply with the European cookie law using tarteaucitron.js.

The module doesn't sufficiently filter user-supplied markup inside of content leading to an attacker being able to delete arbitrary cookies.

This vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page.

For additional information, see the [Github Security Advisory GHSA-jxj7-g6gm-49j7](https://github.com/AmauriC/tarteaucitron.js/security/advisories/GHSA-jxj7-g6gm-49j7) for the tarteaucitron.js library.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/tacjs

Related threats