Impact
TripleLift’s video-bundle.js ad rendering script permits DOM‑based cross‑site scripting. An unauthenticated attacker can craft postMessage payloads that the script accepts without checking the message origin, allowing the execution of arbitrary JavaScript in the context of a publisher’s domain. The malicious code can hijack the victim’s session and perform unauthorized DOM manipulation.
Affected Systems
The flaw resides in TripleLift’s video‑bundle.js component, which is deployed on publisher web pages that embed TripleLift ads. No specific version details are provided, so any page that loads this script is potentially vulnerable.
Risk and Exploitability
The CVSS score of 2.3 indicates low impact and difficulty; the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a victim to visit a publisher page that includes the script while the attacker controls a separate page that sends a crafted postMessage event. Because the attack is unauthenticated but relies on normal browser behavior, the risk is low, yet the ability to execute user‑supplied code in the publisher’s domain remains a concern.
OpenCVE Enrichment