A vulnerability, which was classified as critical, was found in prebid-universal-creative 1.17.3. The affected element is an unknown function of the file Prebid.js of the component JavaScript API. The manipulation results in embedded malicious code.

This vulnerability is reported as CVE-2025-59039. The attack can be launched remotely. No exploit exists.