CVE-2026-82019: Triplelift Video-Bundle.js

Medium severity, CVSS 4.2. EPSS: 0.3% chance of exploitation in the next 30 days.

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage payloads without origin validation. Attackers can cause a victim to visit an attacker-controlled page that sends malicious postMessage events to a publisher page running the ad script, enabling session hijacking and unauthorized DOM manipulation.

Affected products

  • Triplelift Video-Bundle.js: before 2026-04-28 (fixed in 2026-04-28)

Published 2026-09-14. Last modified 2026-09-24.