Description
CryptoJS.lib.WordArray.random() in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 and 2^47 possibilities — small enough to enumerate on commodity hardware.
Recommendation
Update the crypto-js package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.0.0
- Patched version(s): 4.0.0
References
Could your website be exposed too?
SmartScanner can check your website for crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain and gives you actionable findings to investigate.
Start a free scanRelated Issues
- enclave-vm Vulnerable to Sandbox Escape via Host Error Prototype Chain - CVE-2026-22686
- open-webui Vulnerable to Stored XSS via Model Description - CVE-2026-44721
- Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer - CVE-2026-41680
- React Router vulnerable to Denial of Service via reflected user input in single-fetch - CVE-2026-34077


