{"id":"CVE-2021-43785","aliases":["GHSA-f34m-x9pj-62vq"],"url":"https://o3.security/vulnerability/CVE-2021-43785","summary":"Cross-Site Scripting Vulnerability in @joeattardi/emoji-button","details":"@joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious code.","published":"2021-11-26T19:15:08.077Z","modified":"2026-08-27T08:15:13.625758Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.01014,"percentile":0.6012,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@joeattardi/emoji-button","fixedVersion":"4.6.2"}],"fix":{"url":"https://github.com/joeattardi/emoji-button/commit/05970c09180cd27fff493e998ac5bf0468b1bb16","label":"joeattardi/emoji-button@05970c0"},"references":[{"type":"ADVISORY","url":"https://github.com/joeattardi/emoji-button/security/advisories/GHSA-f34m-x9pj-62vq"},{"type":"FIX","url":"https://github.com/joeattardi/emoji-button/commit/05970c09180cd27fff493e998ac5bf0468b1bb16"},{"type":"FIX","url":"https://github.com/joeattardi/emoji-button/commit/fe54bef107eb3f74873a4018f2ff49fa124c6a2e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T08:15:13.625758Z"}}