MEDIUM4.3
GHSA-mwcw-c2x4-8c55
Predictable results in nanoid generation when given non-integer values
Quick fix
GHSA-mwcw-c2x4-8c55 — nanoid: upgrade to the fixed version with the command below.
npm install nanoid@5.0.9Details
When nanoid is called with a fractional value, there were a number of undesirable effects:
1. in browser and non-secure, the code infinite loops on while (size--) 2. in node, the value of poolOffset becomes fractional, causing calls to nanoid to return zeroes until the pool is next filled 3. if the first call in node is a fractional argument, the initial buffer allocation fails with an error
Version 3.3.8 and 5.0.9 are fixed.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-55565[ADVISORY]
- https://github.com/ai/nanoid/pull/510[WEB]
- https://github.com/ai/nanoid[PACKAGE]
- https://github.com/ai/nanoid/compare/3.3.7...3.3.8[WEB]
- https://github.com/ai/nanoid/releases/tag/5.0.9[WEB]
- https://lists.debian.org/debian-lts-announce/2024/12/msg00025.html[WEB]
- https://lists.debian.org/debian-lts-announce/2025/01/msg00006.html[WEB]