← Vulnerability Intelligence

CVE-2020-36732

crypto-js uses insecure random numbers

medium entropyCVE-2020-36732GHSA-3w3w-pxmm-2w2j

Entropy / wallet impact

crypto-js: The crypto-js package 3.2.0 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.

Description

The crypto-js package 3.2.0 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.

Affected

KindNameEcosystemVersions
packagecrypto-jsnpm= 3.2.0

CWE

CWE-331CWE-330

Primary sources

Published
2023-06-12T02:15:48Z
Last modified
2026-03-16T21:46:39Z
First seen here
2026-08-18T15:11:37Z
CVSS
5.3 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (ghsa)
Credibility
official_cve