CVE-2025-59039

CRITICAL

PUC <1.17.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The maintainers of PUC unpublished version 1.17.3. Users should see Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 as soon as possible to avoid similar attacks in the future.

Scores

CVSS v4 9.3
EPSS 0.0007
EPSS Percentile 22.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-506
Status published
Products (2)
npm/prebid-universal-creative npm
prebid/prebid-universal-creative = 1.17.3
Published Sep 09, 2025
Tracked Since Feb 18, 2026