{"api_version":"v1","generated_at":"2026-10-05T13:55:00+00:00","product":{"cve_count":4,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-dicebear-dicebear-eef196640e85","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/dicebear","name":"dicebear","next_cursor":null,"observations":[{"affected":"dicebear: < 9.4.3","affected_versions_present":true,"cve_id":"CVE-2026-68921","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-68921","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T11:32:29.303Z","patch_url":"","primary_source":"","published":"2026-08-20T21:08:43.813Z"},{"affected":"< 9.4.2","affected_versions_present":true,"cve_id":"CVE-2026-33418","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33418","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T15:11:51.489Z","patch_url":"https://github.com/dicebear/dicebear/security/advisories/GHSA-7j2x-32w6-p43p","primary_source":"","published":"2026-03-24T13:25:57.540Z"},{"affected":">= 5.0.0, < 5.4.4; >= 6.0.0, < 6.1.4; >= 7.0.0, < 7.1.4; >= 8.0.0, < 8.0.3; >= 9.0.0, < 9.4.1","affected_versions_present":true,"cve_id":"CVE-2026-33311","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33311","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-26T13:06:31.409Z","patch_url":"","primary_source":"","published":"2026-03-24T13:23:43.289Z"},{"affected":"< 9.4.0","affected_versions_present":true,"cve_id":"CVE-2026-29112","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-29112","fixed":"9.4.0.","last_modified":"2026-03-18T20:03:09.619Z","patch_url":"https://github.com/dicebear/dicebear/commit/42a59eac46a3c68598859e608ec45e578b27614a","primary_source":"","published":"2026-03-18T02:19:56.503Z"}],"source_generated_at":"2026-10-05T06:20:29.126Z","vendor":"dicebear"}}
