VDB
Sign up

package

npm/@dicebear/core

pkg:npm/%40dicebear/core

MEDIUM4.7npm
GHSA-gcr2-9v8m-gq45· CVE-2026-68921

DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials)

Modified: 9/17/2026