GHSA-f34m-x9pj-62vq
Cross-Site Scripting Vulnerability in @joeattardi/emoji-button
Quick fix
GHSA-f34m-x9pj-62vq — @joeattardi/emoji-button: upgrade to the fixed version with the command below.
npm install @joeattardi/emoji-button@4.6.2Details
### Impact
There are two vectors for XSS attacks with versions of @joeattardi/emoji-button before 4.6.2:
- A URL for a custom emoji - An i18n string
In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious code.
### Patches
This vulnerability is fixed starting in version 4.6.2. This is resolved by properly escaping strings that are inserted into the HTML document.
### Workarounds
There is no workaround other than upgrading to a non-vulnerable version.
### Credit
This issue was discovered by GitHub team member [@erik-krogh (Erik Krogh Kristensen)](https://github.com/erik-krogh) and was reported by the GitHub Security Lab team.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 4.6.2npm install @joeattardi/emoji-button@4.6.2References
- https://github.com/joeattardi/emoji-button/security/advisories/GHSA-f34m-x9pj-62vq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-43785[ADVISORY]
- https://github.com/joeattardi/emoji-button/commit/05970c09180cd27fff493e998ac5bf0468b1bb16[WEB]
- https://github.com/joeattardi/emoji-button/commit/fe54bef107eb3f74873a4018f2ff49fa124c6a2e[WEB]
- https://github.com/joeattardi/emoji-button[PACKAGE]