GHSA-mr9r-mww3-v6gv
SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials
Quick fix
GHSA-mr9r-mww3-v6gv — @dicebear/core: upgrade to the fixed version with the command below.
npm install @dicebear/core@5.4.4Details
## Summary
SVG attribute values derived from user-supplied options (`backgroundColor`, `fontFamily`, `textColor`) were not XML-escaped before interpolation into SVG output. This could allow Cross-Site Scripting (XSS) when applications pass untrusted input to `createAvatar()` and serve the resulting SVG inline or with `Content-Type: image/svg+xml`.
## Affected packages
- **`@dicebear/core`** — `backgroundColor` option values interpolated into SVG attributes without escaping (affects `solid` and `gradientLinear` background types) - **`@dicebear/initials`** — `fontFamily` and `textColor` option values interpolated into SVG attributes without escaping
## Fix
All affected SVG attribute values are now properly escaped using XML entity encoding. Users should upgrade to the listed patched versions.
## Mitigating factors
- Applications that validate input against the library's JSON Schema before passing it to `createAvatar()` are not affected - The DiceBear CLI validates input via AJV and was not vulnerable - Exploitation requires that an application passes untrusted, unvalidated external input directly as option values
Are you affected?
Enter the version of the package you're using.