Vulnerabilities/

crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain

Severity:
High

Description

CryptoJS.lib.WordArray.random() in affected versions is not a cryptographically secure random number generator. Nominal requests for 128 or 256 bits of entropy produce effective search spaces of approximately 2^39 and 2^47 possibilities — small enough to enumerate on commodity hardware.

Recommendation

Update the crypto-js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
crypto-js
Anything's wrong? Let us know Last updated on August 07, 2026