LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-33311

dicebear · dicebear

Published
CVSS4.7
Severitymedium
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

DiceBear is an avatar library for designers and developers. Starting in version 5.0.0 and prior to versions 5.4.4, 6.1.4, 7.1.4, 8.0.3, and 9.4.1, SVG attribute values derived from user-supplied options (`backgroundColor`, `fontFamily`, `textColor`) were not XML-escaped before interpolation into SVG output. This could allow Cross-Site Scripting (XSS) when applications pass untrusted input to `createAvatar()` and serve the resulting SVG inline or with `Content-Type: image/svg+xml`. Starting in versions 5.4.4, 6.1.4, 7.1.4, 8.0.3, and 9.4.1, all affected SVG attribute values are properly escaped using XML entity encoding. Users should upgrade to the listed patched versions. Some mitigating fac

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33311

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33311.