MEDIUM
dicebear
CVE published 2026-08-20
CVE-2026-68921
The @dicebear/core and @dicebear/initials libraries prior to version 9.4.3 are vulnerable to SVG injection attacks due to a lack of XML escaping in the addRotate function of @dicebear/core and the emission of fontSize and fontWeight without escaping in @dicebear/initials. This issue allows attackers to inject arbitrary SVG markup, potentially leading to script execution in the page origin when the generat [truncated]