CVE-2021-23566

MEDIUM

nanoid <3.1.31 - Info Disclosure

Title source: llm
STIX 2.1

Description

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

Scores

CVSS v3 4.0
EPSS 0.0003
EPSS Percentile 7.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-704
Status published
Products (2)
nanoid_project/nanoid 3.0.0 - 3.1.31
npm/nanoid 3.0.0 - 3.1.31npm
Published Jan 14, 2022
Tracked Since Feb 18, 2026