GHSA-gcr2-9v8m-gq45: XSS
Summary
@dicebear/core builds avatar SVGs from caller-supplied options. The numeric rotate option is interpolated into an SVG transform attribute without XML-escaping. It is typed as a number, but nothing checks the type at runtime, so a string value passes straight through and can break out of the attribute to inject arbitrary SVG markup.
This is the same root cause as CVE-2026-33311 (GHSA-mr9r-mww3-v6gv), which escaped the string options backgroundColor, fontFamily, and textColor but did not cover rotate. @dicebear/initials has the same gap in its numeric fontSize and fontWeight options.
Impact
Cross-site scripting (CWE-79). When the generated avatar is rendered inline (for example via innerHTML) or served as image/svg+xml and opened directly, injected markup such as an <image onerror> handler runs script in the page's origin.
Exploitation requires the application to pass untrusted input into one of these options:
- rotate (@dicebear/core) - fontSize, fontWeight (@dicebear/initials)
In most integrations these options are set by the developer and only seed is user-controlled, so the vulnerable configuration is uncommon. Applications that use trusted, hardcoded values for these options are not at risk.
Patches
Fixed in @dicebear/core 9.4.3 and @dicebear/initials 9.4.3: the values are now XML-escaped before being written into the SVG, matching the CVE-2026-33311 fix. Upgrade to 9.4.3 or later.
The 5.x through 8.x lines share the same flaw but are end-of-life and will not receive a backport; upgrade to 9.4.3. The 10.x line is not affected.
Workarounds
If you cannot upgrade, coerce the affected options to a number before passing them to createAvatar:
js rotate: Number(userInput) || 0,
Credits
Reported by @rz1027.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@dicebear/initialsto a version that resolves this vulnerability.Fixed in 9.4.3 - Upgrade
Upgrade
npm/@dicebear/coreto a version that resolves this vulnerability.Fixed in 9.4.3 - Upgrade
Upgrade
@dicebear/coreto a version that resolves this vulnerability.Fixed in 9.4.3 - Upgrade
Upgrade
@dicebear/initialsto a version that resolves this vulnerability.Fixed in 9.4.3 - Configuration
If you cannot upgrade, coerce the numeric rotate option to a number before passing it to createAvatar (e.g., use `rotate: Number(userInput) || 0`), because a string value passes through at runtime and can break out of the SVG `transform` attribute for injection.
@dicebear/core/@dicebear/initials rotate = Number(userInput) || 0
Event History
Frequently Asked Questions
Which applications are realistically exposed?
Applications are exposed when untrusted input can reach the rotate option in @dicebear/core or the fontSize or fontWeight options in @dicebear/initials, and the resulting SVG is rendered inline or opened directly as image/svg+xml. The advisory notes that this is uncommon in most integrations because developers usually set these options while only the seed is user-controlled.
What must an attacker control to exploit this issue?
An attacker must be able to supply a string value to one of the affected numeric options despite its declared numeric type. Runtime type checking is absent, allowing the string to escape the SVG attribute and inject SVG markup.
How can I determine whether my implementation is affected?
Review all calls that generate DiceBear avatars and trace whether untrusted data is passed to rotate, fontSize, or fontWeight. Prioritize cases where the generated SVG is inserted with innerHTML or otherwise rendered inline, or is served as image/svg+xml for direct opening.