Vulnerabilities/

tarteaucitron.js vulnerable to DOM Clobbering via document.currentScript

Severity:
Medium

Description

A vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element such as:

it could clobber the document.currentScript property.

Recommendation

Update the tarteaucitronjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
tarteaucitronjs
Anything's wrong? Let us know Last updated on July 03, 2025

This issue is available in SmartScanner Professional

See Pricing