Dicebear is an avatar-generation service whose vulnerabilities center on its eponymous product and reflect weaknesses typical of web-facing generation tools: resource-exhaustion issues, cross-site scripting, and improper regular-expression handling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dicebear over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33418HIGH DiceBear is an avatar library for designers and developers. Prior to version 9.4.2, the `ensureSize()` function in `@dicebear/converter` used a regex-based approach to rewrite SVG | Mar 24, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-29112HIGH DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dicebear/converter` read the `width` and `height` attributes fr | Mar 18, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-33311MEDIUM DiceBear is an avatar library for designers and developers. Starting in version 5.0.0 and prior to versions 5.4.4, 6.1.4, 7.1.4, 8.0.3, and 9.4.1, SVG attribute values derived from | Mar 24, 2026 | 4.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dicebear.
Media articles that mention a CVE ID that affects a product developed by Dicebear — matched by CVE ID, not by vendor name.