| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jxj7-g6gm-49j7 | tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 28 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amauri
Amauri tarteaucitronjs |
|
| Vendors & Products |
Amauri
Amauri tarteaucitronjs |
Mon, 20 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check whether the element is a legitimate tarteaucitron button or whether the cookie corresponds to a service handled by tarteaucitron. If an attacker can write HTML with data attributes, an element with data-cookie can silently delete a non-HttpOnly cookie with a known name when clicked by a user. This issue is fixed in version 1.33.0. | |
| Title | tarteaucitron.js: data-cookie attribute can be used to delete arbitrary cookies | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-20T19:11:28.659Z
Reserved: 2026-06-02T18:30:51.281Z
Link: CVE-2026-49977
Updated: 2026-07-17T20:23:26.752Z
Status : Deferred
Published: 2026-07-17T21:17:06.930
Modified: 2026-07-23T18:08:15.870
Link: CVE-2026-49977
No data.
OpenCVE Enrichment
Updated: 2026-07-30T23:30:08Z
Github GHSA