CVE-2021-23566

MEDIUM

nanoid 3.0.0-3.1.30 - Information Exposure via valueOf() Function

Title source: llm
STIX 2.1

Description

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

References (7)

Core 7
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-NANOID-2332193
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2332550
Exploit, Third Party Advisory x_refsource_misc
https://gist.github.com/artalar/bc6d1eb9a3477d15d2772e876169a444
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://github.com/ai/nanoid/pull/328

Scores

CVSS v3 4.0
EPSS 0.0044
EPSS Percentile 34.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-704
Status published
Products (2)
nanoid_project/nanoid 3.0.0 - 3.1.31
npm/nanoid 3.0.0 - 3.1.31npm
Published Jan 14, 2022
Tracked Since Feb 18, 2026