MEDIUM5.3npm
GHSA-3w3w-pxmm-2w2j· CVE-2020-36732crypto-js uses insecure random numbers
Modified: 3/16/2026
package
pkg:npm/crypto-js
crypto-js uses insecure random numbers
Modified: 3/16/2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
Modified: 8/7/2026
crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
Modified: 9/10/2026