Junglewise Threat Intelligence

CVE-2021-43785: joeattardi emoji-button cross-site scripting

CVE-2021-43785 · Severity: low · CVSS 3.1 · Published 2021-12-01

Vendors: npm.

Executive brief

The @joeattardi/emoji-button library is a JavaScript component used to add emoji selection functionality to web applications. A cross-site scripting (XSS) vulnerability in versions before 4.6.2 allows attackers to inject malicious scripts through custom emoji URLs or internationalization strings, potentially enabling account takeover, session hijacking, or theft of sensitive user data.

Technical details

The vulnerability is a stored or reflected XSS flaw (CWE-79) caused by insufficient input sanitization when inserting custom emoji URLs and i18n strings into the HTML document. An attacker can craft malicious values that inject script tags into the page, allowing arbitrary JavaScript execution in the browser context of affected users. The vulnerability requires user interaction (UI:R) and network access, but no authentication. The issue was patched in version 4.6.2 by properly escaping all user-controlled strings before HTML insertion.

Affected products

  • joeattardi emoji-button before 4.6.2

Timeline

  • 2021-11-26: disclosed: NVD published
  • 2021-12-01: disclosed: GHSA advisory published
  • 2021-11-26: patched: Version 4.6.2 released with fix

References