Description
The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4003-1 | node-postcss security update |
Debian DLA |
DLA-4013-1 | node-mocha security update |
EUVD |
EUVD-2022-0677 | The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated. |
Github GHSA |
GHSA-qrpm-p2h7-hrv2 | Exposure of Sensitive Information to an Unauthorized Actor in nanoid |
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.4::el8 |
Mon, 19 Aug 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-11-03T21:44:38.677Z
Reserved: 2021-01-08T00:00:00.000Z
Link: CVE-2021-23566
No data.
Status : Modified
Published: 2022-01-14T20:15:10.093
Modified: 2025-11-03T22:15:47.710
Link: CVE-2021-23566
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA