The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
References
Configurations
History
03 Nov 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2022-01-14 20:15
Updated : 2025-11-03 22:15
NVD link : CVE-2021-23566
Mitre link : CVE-2021-23566
CVE.ORG link : CVE-2021-23566
JSON object : View
Products Affected
nanoid_project
- nanoid
CWE
CWE-704
Incorrect Type Conversion or Cast
