Executive brief
@dicebear/converter is a JavaScript library used to convert avatar SVG images to various formats (PNG, JPEG, WebP, AVIF). An attacker can bypass the library's built-in safeguard that limits SVG dimensions to 2048 pixels by injecting XML comments before the actual SVG element. When a Node.js application processes malicious SVG without proper bounds, it can allocate gigabytes of memory and crash, causing service unavailability.
Technical details
The vulnerability is an improper regular expression (CWE-185) in the ensureSize() function, which uses a non-global regex to rewrite SVG width/height attributes and cap them at 2048px. An attacker can craft SVG input that causes the regex to match a dummy <svg tag inside an XML comment instead of the actual SVG root element, leaving the real dimensions unclamped. When the Node.js rendering path (toPng, toJpeg, toWebp, toAvif) calls renderAsync() from @resvg/resvg-js without a fitTo constraint, the SVG renders at attacker-controlled dimensions, potentially allocating gigabytes of memory and causing an out-of-memory crash (DoS). The browser code path is not affected because it enforces the clamped size via canvas.width/canvas.height. The fix replaces regex processing with XML-aware parsing using fast-xml-parser and adds a fitTo constraint to renderAsync() calls.
Affected products
- DiceBear @dicebear/converter <= 9.4.1
Timeline
- 2026-03-20: disclosed: GitHub advisory published
- 2026-03-20: patched: Fixed in version 9.4.2