tarteaucitron: data-cookie attribute can be used to delete arbitrary cookies
- Severity:
- Medium
Description
tarteaucitron provides a list of cookies and buttons to delete them. If an attacker can write HTML with data attributes, they could create an element that silently deletes a cookie when clicked and trick a user to delete this cookie.
Recommendation
Update the tarteaucitronjs package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.33.0
- Patched version(s): 1.33.0
References
Related Issues
- tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability - CVE-2026-22809
- JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection - CVE-2026-46625
- Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser - CVE-2026-47430
- SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user - CVE-2026-34524
You might also like:
- Tags:
- npm
- tarteaucitronjs
Anything's wrong? Let us know Last updated on July 10, 2026


