GHSA-mr9r-mww3-v6gv

Suggest an improvement
Source
https://github.com/advisories/GHSA-mr9r-mww3-v6gv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mr9r-mww3-v6gv
Aliases
Downstream
CGA (4)
Published
2026-03-19T17:49:28Z
Modified
2026-09-10T03:51:00Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials
Details

Summary

SVG attribute values derived from user-supplied options (backgroundColor, fontFamily, textColor) were not XML-escaped before interpolation into SVG output. This could allow Cross-Site Scripting (XSS) when applications pass untrusted input to createAvatar() and serve the resulting SVG inline or with Content-Type: image/svg+xml.

Affected packages

  • @dicebear/core — backgroundColor option values interpolated into SVG attributes without escaping (affects solid and gradientLinear background types)
  • @dicebear/initials — fontFamily and textColor option values interpolated into SVG attributes without escaping

Fix

All affected SVG attribute values are now properly escaped using XML entity encoding. Users should upgrade to the listed patched versions.

Mitigating factors

  • Applications that validate input against the library's JSON Schema before passing it to createAvatar() are not affected
  • The DiceBear CLI validates input via AJV and was not vulnerable
  • Exploitation requires that an application passes untrusted, unvalidated external input directly as option values
Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-19T17:49:28Z",
    "nvd_published_at":  "2026-03-24T14:16:30Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm
@dicebear/core

Package

Name
@dicebear/core
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/core

Affected ranges

Type
SEMVER
Events
Introduced
5.0.0
Fixed
5.4.4

Database specific

last_known_affected_version_range
"<= 5.4.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"
@dicebear/core

Package

Name
@dicebear/core
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/core

Affected ranges

Type
SEMVER
Events
Introduced
6.0.0
Fixed
6.1.4

Database specific

last_known_affected_version_range
"<= 6.1.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"
@dicebear/core

Package

Name
@dicebear/core
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/core

Affected ranges

Type
SEMVER
Events
Introduced
7.0.0
Fixed
7.1.4

Database specific

last_known_affected_version_range
"<= 7.1.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"
@dicebear/core

Package

Name
@dicebear/core
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/core

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.0.3

Database specific

last_known_affected_version_range
"<= 8.0.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"
@dicebear/core

Package

Name
@dicebear/core
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/core

Affected ranges

Type
SEMVER
Events
Introduced
9.0.0
Fixed
9.4.1

Database specific

last_known_affected_version_range
"<= 9.4.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"
@dicebear/initials

Package

Name
@dicebear/initials
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/initials

Affected ranges

Type
SEMVER
Events
Introduced
5.0.0
Fixed
5.4.4

Database specific

last_known_affected_version_range
"<= 5.4.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"
@dicebear/initials

Package

Name
@dicebear/initials
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/initials

Affected ranges

Type
SEMVER
Events
Introduced
6.0.0
Fixed
6.1.4

Database specific

last_known_affected_version_range
"<= 6.1.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"
@dicebear/initials

Package

Name
@dicebear/initials
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/initials

Affected ranges

Type
SEMVER
Events
Introduced
7.0.0
Fixed
7.1.4

Database specific

last_known_affected_version_range
"<= 7.1.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"
@dicebear/initials

Package

Name
@dicebear/initials
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/initials

Affected ranges

Type
SEMVER
Events
Introduced
8.0.0
Fixed
8.0.3

Database specific

last_known_affected_version_range
"<= 8.0.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"
@dicebear/initials

Package

Name
@dicebear/initials
View open source insights on deps.dev
Purl
pkg:npm/%40dicebear/initials

Affected ranges

Type
SEMVER
Events
Introduced
9.0.0
Fixed
9.4.1

Database specific

last_known_affected_version_range
"<= 9.4.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"