CVE-2026-95100

Use of Cryptographically Weak Pseudo-Random Number Generator in the npm package random-token

Affected package: random-token (npm), 0.0.8 and all earlier versions.

Weakness: CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator.

Fixed version: none available. See Maintenance status below.

Usage at the time of reporting: around 7,100 downloads a week.

What the problem is

random-token is published as a token generator. Every character of its output is selected using Math.random() (index.js). Math.random() is not a cryptographic generator: in V8 it is an xorshift128+ stream whose internal state can be recovered from a modest number of observed outputs, a result that is well established in public research. The generated tokens are therefore fully determined by that stream.

Impact

The package name and description invite use for session identifiers, password reset links, email verification links and API keys. Where it is used for any of those, someone who observes a number of issued tokens can recover the generator state and derive other tokens, including ones already issued to other users. This is a predictability weakness, not a code execution one.

How to fix it

Generate tokens from a cryptographic source: crypto.randomBytes() or crypto.randomInt() in Node, or crypto.getRandomValues() in a browser. Established libraries such as nanoid and crypto-random-string already do this. Math.random() should not be used for any value that carries security meaning.

Until a fixed release exists, projects depending on this package should either apply the change in a fork or move to a maintained alternative that does not build shell command strings from caller-supplied values.

Maintenance status

The latest release, 0.0.8, was published in April 2014, and the repository was last updated in February 2014. It carries no security policy and no private reporting channel, so the report was made to MITRE as CNA of last resort. No fixed version is available.

Timeline

Credit and method

Reported by Brian Willows, Graith Internet. The finding and its analysis were AI-assisted, using Claude, and every claim was verified locally against the published package before the report was filed. The verification detail is held privately and is available to a maintainer or to a CVE numbering authority on request.

References

This advisory is published so that the CVE record has a public reference. Corrections are welcome at security@graith.co.uk.