Vulnerabilities/

Insufficient Entropy in cryptiles

Severity:
High

Description

Versions of cryptiles prior to 4.1.2 are vulnerable to Insufficient Entropy. The randomDigits() method does not provide sufficient entropy and its generates digits that are not evenly distributed.

Recommendation

Update the cryptiles package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
cryptiles
Anything's wrong? Let us know Last updated on June 08, 2026