Description
Versions of cryptiles prior to 4.1.2 are vulnerable to Insufficient Entropy. The randomDigits() method does not provide sufficient entropy and its generates digits that are not evenly distributed.
Recommendation
Update the cryptiles package to the latest compatible version. Followings are version details:
Affected version(s): **>= 3.1.0, < 3.1.3 >= 4.0.0, < 4.1.2** Patched version(s): **3.1.3 4.1.2**
References
Could your website be exposed too?
SmartScanner can check your website for Insufficient Entropy in cryptiles and gives you actionable findings to investigate.
Start a free scanRelated Issues
- pubnub Insufficient Entropy vulnerability - CVE-2023-26154
- crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain - CVE-2026-71851
- Prototype Pollution in async merge-object - CVE-2018-3753
- Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that - CVE-2026-33468
You might also like:
See something that needs correcting? Let us knowUpdated June 08, 2026


