But if you're embedding a JS library from a CDN, then as a matter of fact, you aren't passing any data about your user to the third party at all. The user's browser is doing that as part of its normal operation.
Moreover, as another matter of fact, you cannot have either any knowledge or any control over what happens next regarding any personal data the third party is collecting or how it is being processed, unless you have some separate arrangement with the third party that goes well beyond mere linking or embedding.
Logically, it doesn't seem to make much sense for you to be either the controller or the processor in that instance. However, if the third party plays either role, they may have no mechanism to communicate with your site visitor to fulfil their obligations either.