Intel

AIKIDO-2024-10056

emoji-mart is vulnerable to Memory Leak

Memory Leak Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 26, 2024

5

Low Risk

This Affects:

JSemoji-mart
5.3.0 - 5.5.2
Fixed in 5.6.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to a missing release of resource after effective lifetime. In the Picker component, one of the event listeners was never removed, potentially causing a memory leak.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

emoji-mart is vulnerable to Memory Leak in versions 5.3.0 - 5.5.2.

How to fix this

Upgrade the emoji-mart library to the patch version.