Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest were briefly affected by crypto-related malware. This includes the extremely popular jsdelivr hosting of this file. The maintainers of PUC unpublished version 1.17.3. Users should see Prebid.js 9 release notes for suggestions on moving off the deprecated workflow of using the PUC or pointing to a dynamic version of it. PUC users pointing to latest should transition to 1.17.2 as soon as possible to avoid similar attacks in the future.
CVSS
No CVSS.
References
Configurations
No configuration.
History
09 Sep 2025, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-09 23:15
Updated : 2025-09-11 17:14
NVD link : CVE-2025-59039
Mitre link : CVE-2025-59039
CVE.ORG link : CVE-2025-59039
JSON object : View
Products Affected
No product.
CWE
CWE-506
Embedded Malicious Code