CVE-2026-82019: TripleLift video-bundle.js DOM-based XSS via postMessage

Published Sep 14, 2026
·
Updated

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage payloads without origin validation. Attackers can cause a victim to visit an attacker-controlled page that sends malicious postMessage events to a publisher page running the ad script, enabling session hijacking and unauthorized DOM manipulation.

Affected Software

1 affected component
TripleLift video-bundle.js

Event History

Sep 14, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Publisher pages that run TripleLift's video-bundle.js are exposed. An attacker targets visitors to those pages rather than needing an account on the publisher site.

2

What does an attacker need to exploit it?

The attacker needs to persuade a victim to visit an attacker-controlled page that sends a crafted postMessage payload to a publisher page running the affected script. No authentication is required, but victim interaction is required.

3

What could successful exploitation allow?

Successful exploitation can execute arbitrary JavaScript in the publisher's domain. The described impacts include session hijacking and unauthorized manipulation of the page DOM.

4

How is the vulnerability enabled?

The script processes postMessage payloads without validating their origin. Crafted message content can therefore reach a DOM-based XSS condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203