PT-2026-46080 · Packagist · Drupal/Tacjs

Published

2026-06-03

·

Updated

2026-06-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module enables sites to comply with the European cookie law using tarteaucitron.js.
The module doesn't sufficiently filter user-supplied markup inside of content leading to an attacker being able to delete arbitrary cookies.
This vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page.

Related Identifiers

DRUPAL-CONTRIB-2026-040

Affected Products

Drupal/Tacjs