CVE-2026-68921 | DiceBear up to 9.4.2 SVG Generation svg.ts addRotate rotate injection

SecurityVulns

A vulnerability was found in DiceBear up to 9.4.2. It has been classified as critical. This issue affects the function addRotate of the file packages/@dicebear/core/src/utils/svg.ts of the component SVG Generation. The manipulation of the argument rotate leads to injection.

This vulnerability is documented as CVE-2026-68921. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More