Description
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
Scores
CVSS v3
4.0
EPSS
0.0003
EPSS Percentile
7.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-704
Status
published
Products (2)
nanoid_project/nanoid
3.0.0 - 3.1.31
npm/nanoid
3.0.0 - 3.1.31npm
Published
Jan 14, 2022
Tracked Since
Feb 18, 2026