PatchSiren

dicebear CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM dicebear CVE published 2026-08-20

CVE-2026-68921

The @dicebear/core and @dicebear/initials libraries prior to version 9.4.3 are vulnerable to SVG injection attacks due to a lack of XML escaping in the addRotate function of @dicebear/core and the emission of fontSize and fontWeight without escaping in @dicebear/initials. This issue allows attackers to inject arbitrary SVG markup, potentially leading to script execution in the page origin when the generat [truncated]