Description
Versions of cryptiles prior to 4.1.2 are vulnerable to Insufficient Entropy. The randomDigits() method does not provide sufficient entropy and its generates digits that are not evenly distributed.
Recommendation
Update the cryptiles package to the latest compatible version. Followings are version details:
Affected version(s): **>= 3.1.0, < 3.1.3 >= 4.0.0, < 4.1.2** Patched version(s): **3.1.3 4.1.2**
References
Related Issues
- pubnub Insufficient Entropy vulnerability - CVE-2023-26154
- crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain - CVE-2026-71851
- Prototype Pollution in async merge-object - CVE-2018-3753
- Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that - CVE-2026-33468
You might also like:
- Tags:
- npm
- cryptiles
Anything's wrong? Let us know Last updated on June 08, 2026


