Affected package: random-token (npm), 0.0.8 and all earlier versions.
Weakness: CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator.
Fixed version: none available. See Maintenance status below.
Usage at the time of reporting: around 7,100 downloads a week.
What the problem is
random-token is published as a token generator. Every character of
its output is selected using Math.random() (index.js).
Math.random() is not a cryptographic generator: in V8 it is an xorshift128+ stream
whose internal state can be recovered from a modest number of observed outputs, a result that is
well established in public research. The generated tokens are therefore fully determined by that
stream.
Impact
The package name and description invite use for session identifiers, password reset links, email verification links and API keys. Where it is used for any of those, someone who observes a number of issued tokens can recover the generator state and derive other tokens, including ones already issued to other users. This is a predictability weakness, not a code execution one.
How to fix it
Generate tokens from a cryptographic source: crypto.randomBytes() or
crypto.randomInt() in Node, or crypto.getRandomValues() in a browser.
Established libraries such as nanoid and crypto-random-string already do this.
Math.random() should not be used for any value that carries security meaning.
Until a fixed release exists, projects depending on this package should either apply the change in a fork or move to a maintained alternative that does not build shell command strings from caller-supplied values.
Maintenance status
The latest release, 0.0.8, was published in April 2014, and the repository was last updated in February 2014. It carries no security policy and no private reporting channel, so the report was made to MITRE as CNA of last resort. No fixed version is available.
Timeline
- 10 September 2026: reported to MITRE as CNA of last resort, the affected project having no security policy and no private reporting channel.
- 29 September 2026: CVE ID assigned.
- 30 September 2026: this advisory published as the public reference for the CVE record.
Credit and method
Reported by Brian Willows, Graith Internet. The finding and its analysis were AI-assisted, using Claude, and every claim was verified locally against the published package before the report was filed. The verification detail is held privately and is available to a maintainer or to a CVE numbering authority on request.
References
This advisory is published so that the CVE record has a public reference. Corrections are welcome at security@graith.co.uk.
