CVE-2020-36732: Crypto-Js Project Crypto-Js
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
Affected products
- Crypto-Js Project Crypto-Js: before 3.2.1 (fixed in 3.2.1)
Published 2023-06-12. Last modified 2026-06-17.