CVE-2026-77166

low

Description

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

References

https://hackerone.com/reports/3599470

Details

Source: Mitre, NVD

Published: 2026-09-21

Updated: 2026-09-22

Risk Information

CVSS v2

Base Score: 3.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 2.4

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Severity: Low

EPSS

EPSS: 0.00188