PatchSiren

js-cookie CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH js-cookie CVE published 2026-06-10

CVE-2026-46625

CVE-2026-46625 is a vulnerability in the JavaScript Cookie API, specifically in the js-cookie library prior to version 3.0.7. The vulnerability allows an attacker to hijack the prototype of objects, potentially leading to security issues. The issue has been patched in version 3.0.7. Defenders should assess exposure and prioritize upgrading to the patched version. The vulnerability is triggered when the so [truncated]