CVE-2025-31475

MEDIUM

Amauri Tarteaucitronjs < 1.20.1 - Prototype Pollution

Title source: rule
STIX 2.1

Description

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker with direct access to the site's source code or a CMS plugin to manipulate JavaScript object prototypes, leading to potential security risks such as data corruption or unintended code execution. An attacker with high privileges could exploit this vulnerability to modify object prototypes, affecting core JavaScript behavior, cause application crashes or unexpected behavior, or potentially introduce further security vulnerabilities depending on the application's architecture. This vulnerability is fixed in 1.20.1.

Scores

CVSS v3 5.5
EPSS 0.0133
EPSS Percentile 80.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1321
Status published
Products (2)
amauri/tarteaucitronjs < 1.20.1
npm/tarteaucitronjs 0 - 1.20.1npm
Published Apr 07, 2025
Tracked Since Feb 18, 2026