VDB
Sign up
HIGH7.6

GHSA-f34m-x9pj-62vq

Cross-Site Scripting Vulnerability in @joeattardi/emoji-button

Quick fix

GHSA-f34m-x9pj-62vq — @joeattardi/emoji-button: upgrade to the fixed version with the command below.

npm install @joeattardi/emoji-button@4.6.2

Details

### Impact

There are two vectors for XSS attacks with versions of @joeattardi/emoji-button before 4.6.2:

- A URL for a custom emoji - An i18n string

In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious code.

### Patches

This vulnerability is fixed starting in version 4.6.2. This is resolved by properly escaping strings that are inserted into the HTML document.

### Workarounds

There is no workaround other than upgrading to a non-vulnerable version.

### Credit

This issue was discovered by GitHub team member [@erik-krogh (Erik Krogh Kristensen)](https://github.com/erik-krogh) and was reported by the GitHub Security Lab team.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@joeattardi/emoji-button
Introduced in: 0Fixed in: 4.6.2
Fixnpm install @joeattardi/emoji-button@4.6.2

References