{"id":"GHSA-mr9r-mww3-v6gv","summary":"SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials","details":"## Summary\n\nSVG attribute values derived from user-supplied options (`backgroundColor`, `fontFamily`, `textColor`) were not XML-escaped before interpolation into SVG output. This could allow Cross-Site Scripting (XSS) when applications pass untrusted input to `createAvatar()` and serve the resulting SVG inline or with `Content-Type: image/svg+xml`.\n\n## Affected packages\n\n- **`@dicebear/core`** — `backgroundColor` option values interpolated into SVG attributes without escaping (affects `solid` and `gradientLinear` background types)\n- **`@dicebear/initials`** — `fontFamily` and `textColor` option values interpolated into SVG attributes without escaping\n\n## Fix\n\nAll affected SVG attribute values are now properly escaped using XML entity encoding. Users should upgrade to the listed patched versions.\n\n## Mitigating factors\n\n- Applications that validate input against the library's JSON Schema before passing it to `createAvatar()` are not affected\n- The DiceBear CLI validates input via AJV and was not vulnerable\n- Exploitation requires that an application passes untrusted, unvalidated external input directly as option values","aliases":["CVE-2026-33311"],"modified":"2026-09-10T03:51:00.638214758Z","published":"2026-03-19T17:49:28Z","database_specific":{"github_reviewed_at":"2026-03-19T17:49:28Z","nvd_published_at":"2026-03-24T14:16:30Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/dicebear/dicebear/security/advisories/GHSA-mr9r-mww3-v6gv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33311"},{"type":"PACKAGE","url":"https://github.com/dicebear/dicebear"}],"affected":[{"package":{"name":"@dicebear/core","ecosystem":"npm","purl":"pkg:npm/%40dicebear/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.4.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json","last_known_affected_version_range":"\u003c= 5.4.3"}},{"package":{"name":"@dicebear/core","ecosystem":"npm","purl":"pkg:npm/%40dicebear/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.0.0"},{"fixed":"6.1.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 6.1.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"}},{"package":{"name":"@dicebear/core","ecosystem":"npm","purl":"pkg:npm/%40dicebear/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.0.0"},{"fixed":"7.1.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 7.1.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"}},{"package":{"name":"@dicebear/core","ecosystem":"npm","purl":"pkg:npm/%40dicebear/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.0.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 8.0.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"}},{"package":{"name":"@dicebear/core","ecosystem":"npm","purl":"pkg:npm/%40dicebear/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.0.0"},{"fixed":"9.4.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json","last_known_affected_version_range":"\u003c= 9.4.0"}},{"package":{"name":"@dicebear/initials","ecosystem":"npm","purl":"pkg:npm/%40dicebear/initials"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.4.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json","last_known_affected_version_range":"\u003c= 5.4.3"}},{"package":{"name":"@dicebear/initials","ecosystem":"npm","purl":"pkg:npm/%40dicebear/initials"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.0.0"},{"fixed":"6.1.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 6.1.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"}},{"package":{"name":"@dicebear/initials","ecosystem":"npm","purl":"pkg:npm/%40dicebear/initials"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.0.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json","last_known_affected_version_range":"\u003c= 7.1.3"}},{"package":{"name":"@dicebear/initials","ecosystem":"npm","purl":"pkg:npm/%40dicebear/initials"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0"},{"fixed":"8.0.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 8.0.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json"}},{"package":{"name":"@dicebear/initials","ecosystem":"npm","purl":"pkg:npm/%40dicebear/initials"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.0.0"},{"fixed":"9.4.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-mr9r-mww3-v6gv/GHSA-mr9r-mww3-v6gv.json","last_known_affected_version_range":"\u003c= 9.4.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}