{"id":"DRUPAL-CONTRIB-2026-040","details":"This module enables sites to comply with the European cookie law using tarteaucitron.js.\n\nThe module doesn't sufficiently filter user-supplied markup inside of content leading to an attacker being able to delete arbitrary cookies.\n\nThis vulnerability is mitigated by the fact that an attacker needs to be able to insert specific data attributes in the page.\n\nFor additional information, see the [Github Security Advisory GHSA-jxj7-g6gm-49j7](https://github.com/AmauriC/tarteaucitron.js/security/advisories/GHSA-jxj7-g6gm-49j7) for the tarteaucitron.js library.","aliases":[" CVE-2026-49977 "],"modified":"2026-09-10T03:46:11.196499741Z","published":"2026-06-03T16:11:51Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2026-040"}],"affected":[{"package":{"name":"drupal/tacjs","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/tacjs?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.0"}],"database_specific":{"constraint":"\u003c6.8"}}],"database_specific":{"affected_versions":"\u003c6.8","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/tacjs/DRUPAL-CONTRIB-2026-040.json"}}],"schema_version":"1.9.0","credits":[{"name":"Frank Mably (mably)","contact":["https://www.drupal.org/u/mably"]},{"name":"Pierre Rudloff (prudloff)","contact":["https://www.drupal.org/u/prudloff"]}]}