generate-password@1.0.2 vulnerabilities

Easy library for generating unique passwords.

Direct Vulnerabilities

Known vulnerabilities in the generate-password package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cryptographic Backdoor

generate-password is a relatively extensive library for generating random and unique passwords.

Affected versions of this package are vulnerable to Cryptographic Backdoor. It generates random values that are biased towards certain characters depending on the chosen character sets. This may result in guessable passwords.

How to fix Cryptographic Backdoor?

Upgrade generate-password to version 1.4.1 or higher.

<1.4.1