Vulnerability library
Security checkAugust 07, 2026

crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmcrypto-js

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

CryptoJS.lib.WordArray.random() in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 and 2^47 possibilities — small enough to enumerate on commodity hardware.

Recommendation

Update the crypto-js package to the latest compatible version. Followings are version details:

  • Affected version(s): < 4.0.0
  • Patched version(s): 4.0.0

References

Could your website be exposed too?

SmartScanner can check your website for crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated August 07, 2026