CVE-2026-49977: Amauric Tarteaucitron.js

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check whether the element is a legitimate tarteaucitron button or whether the cookie corresponds to a service handled by tarteaucitron. If an attacker can write HTML with data attributes, an element with data-cookie can silently delete a non-HttpOnly cookie with a known name when clicked by a user. This issue is fixed in version 1.33.0.

Affected products

  • Amauric Tarteaucitron.js: before 1.33.0 (fixed in 1.33.0)

Published 2026-07-17. Last modified 2026-07-23.