Executive brief
emojione is a JavaScript library for converting emoji text into images or HTML. Affected versions fail to properly sanitize user input passed to emoji conversion functions, allowing attackers to inject malicious JavaScript code that executes in the context of web applications using the library. This can lead to session hijacking, credential theft, or defacement of user content. Applications using emojione versions prior to 1.3.1 are at risk.
Technical details
emojione contains a cross-site scripting (CWE-79) vulnerability in its emoji conversion functions: toShort(), shortnameToImage(), unicodeToImage(), and toImage(). The root cause is insufficient input sanitization when processing user-supplied emoji text. Attackers can inject malicious HTML and JavaScript through emoji parameters, and the functions do not properly escape the input before inserting it into the DOM or HTML output. The vulnerability is reachable wherever these functions are called with untrusted user input, typically in web applications processing user-submitted emoji or text. An attacker can execute arbitrary JavaScript in the context of the affected application's domain. The vulnerability was patched in version 1.3.1 (released April 2015) with revised escaping functions.
Affected products
- joypixels emojione <=1.3.0
Timeline
- 2020-09-01: disclosed: GHSA-46m8-42hm-wvvw published
- 2015-04-13: patched: Version 1.3.1 released with security fixes