At Salesforce, we understand that the confidentiality, integrity, and availability of your data is vital to your business, and we take the protection of your data very seriously.
What happened?
On June 1, 2023, a security researcher discovered a JavaScript vulnerability affecting the Salesforce tough-cookie open-source NPM project. This vulnerability could allow a malicious actor to attach cookie data to a global namespace, resulting in cookies being exposed to individuals with access to your running code.
What did Salesforce do to address this?
On June 5, a fix was implemented and a release note, available here, was published to GitHub. On June 29, CVE-2023-26136 was issued to address this vulnerability with a CVSS score of 6.5.
How do I know if I am impacted?
To determine if you use the tough-cookie NPM package and are potentially affected by this vulnerability, take the following steps:
If all of the above are not true, then your running instance has not been impacted by the vulnerability.
If I am impacted, what action should I take?
If you determine that you are impacted by this vulnerability, to eliminate potential unauthorized access to your cookies, upgrade tough-cookie to version 4.1.3, available here. Alternatively, you could update your code to ensure all instances of CookieJar have rejectPublicSuffixes set to true, or use an alternative store to MemoryCookieStore.
What should I do if I have questions?
If you have any questions, please open a case with Support via the Help portal.000395871

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.