Description
TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage payloads without origin validation. Attackers can cause a victim to visit an attacker-controlled page that sends malicious postMessage events to a publisher page running the ad script, enabling session hijacking and unauthorized DOM manipulation.
Published: 2026-09-14
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting (XSS)
Action: Apply Fix
AI Analysis

Impact

TripleLift’s video-bundle.js ad rendering script permits DOM‑based cross‑site scripting. An unauthenticated attacker can craft postMessage payloads that the script accepts without checking the message origin, allowing the execution of arbitrary JavaScript in the context of a publisher’s domain. The malicious code can hijack the victim’s session and perform unauthorized DOM manipulation.

Affected Systems

The flaw resides in TripleLift’s video‑bundle.js component, which is deployed on publisher web pages that embed TripleLift ads. No specific version details are provided, so any page that loads this script is potentially vulnerable.

Risk and Exploitability

The CVSS score of 2.3 indicates low impact and difficulty; the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a victim to visit a publisher page that includes the script while the attacker controls a separate page that sends a crafted postMessage event. Because the attack is unauthenticated but relies on normal browser behavior, the risk is low, yet the ability to execute user‑supplied code in the publisher’s domain remains a concern.

Generated by OpenCVE AI on September 15, 2026 at 14:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Contact TripleLift support to obtain an updated video‑bundle.js that validates postMessage origins and apply the patch as soon as it is released.
  • If a fixed script is not yet available, temporarily remove or disable the vulnerable video‑bundle.js from publisher pages until a patch is released.
  • Wrap the script in a sandboxed iframe or use an iframe with the sandbox attribute to isolate it from the main content, limiting the potential impact of any script execution.
  • If modifying the script is unavoidable, add client‑side checks for the message origin before processing any postMessage events to prevent malicious payloads from being executed.

Generated by OpenCVE AI on September 15, 2026 at 14:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Triplelift
Triplelift video-bundle.js
Vendors & Products Triplelift
Triplelift video-bundle.js

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage payloads without origin validation. Attackers can cause a victim to visit an attacker-controlled page that sends malicious postMessage events to a publisher page running the ad script, enabling session hijacking and unauthorized DOM manipulation.
Title TripleLift video-bundle.js DOM-based XSS via postMessage
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Triplelift Video-bundle.js
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T15:32:00.865Z

Reserved: 2026-08-27T21:39:20.459Z

Link: CVE-2026-82019

cve-icon Vulnrichment

Updated: 2026-09-14T15:30:04.399Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T15:17:09.223

Modified: 2026-09-24T20:28:01.780

Link: CVE-2026-82019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')