Loading HuntDB...

GHSA-6g33-f262-xjp4

GitHub Security Advisory

Cryptographically Weak PRNG in randomatic

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Affected versions of `randomatic` generate random values using a cryptographically weak psuedo-random number generator. This may result in predictable values instead of random values as intended.

## Recommendation

Update to version 3.0.0 or later.

Affected Packages

npm randomatic
Affected versions: 0 (fixed in 3.0.0)

Related CVEs

Key Information

GHSA ID
GHSA-6g33-f262-xjp4
Published
October 9, 2018 12:57 AM
Last Modified
September 8, 2023 8:56 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
randomatic
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.