VDB
Sign up
HIGH7.5

GHSA-v3r3-4qgc-vw66

Uncontrolled memory allocation via crafted SVG dimensions in @dicebear/converter

Quick fix

GHSA-v3r3-4qgc-vw66 — @dicebear/converter: upgrade to the fixed version with the command below.

npm install @dicebear/converter@9.4.0

Details

### Impact

The `ensureSize()` function in `@dicebear/converter` (versions < 9.4.0) read the `width` and `height` attributes from the input SVG to determine the output canvas size for rasterization (PNG, JPEG, WebP, AVIF). An attacker who can supply a crafted SVG with extremely large dimensions (e.g. `width="999999999"`) could force the server to allocate excessive memory, leading to denial of service.

This primarily affects server-side applications that pass **untrusted or user-supplied SVGs** to the converter's `toPng()`, `toJpeg()`, `toWebp()`, or `toAvif()` functions. Applications that only convert self-generated DiceBear avatars are not practically exploitable, but are still recommended to upgrade.

### Patches

Fixed in version **9.4.0**. The `ensureSize()` function no longer reads SVG attributes to determine output size. Instead, a new `size` option (default: 512, max: 2048) controls the output dimensions. Invalid values (NaN, negative, zero, Infinity) fall back to the default.

### Workarounds

If upgrading is not immediately possible, validate and sanitize the `width` and `height` attributes of any untrusted SVG input before passing it to the converter.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@dicebear/converter
Introduced in: 0Fixed in: 9.4.0
Fixnpm install @dicebear/converter@9.4.0

References