GHSA-vh45-f885-3848
## Summary `sm-crypto` (npm package **0.4.0**, the latest release, published 2026-01-20) generates SM2 private keys and signing ephemeral scalars from a single module-wide RNG instance (`src/sm2/utils.js`: `const rng = new SecureRandom()`). `SecureRandom` is jsbn's PRNG, which seeds an **ARC4** stream from `window.crypto.getRandomValues` when available. **In Node.js — sm-crypto's primary runtime — `window` is `undefined`, so the CSPRNG branch is skipped** and the seed pool is instead filled from `Math.random()` (V8 `xorshift128+`, recoverable from a few outputs) plus `new Date().getTime()` (wall clock, attacker-estimable). Node *does* expose Web Crypto as `globalThis.crypto`, but jsbn checks `window.crypto`, not `globalThis.crypto`, so the secure path is never taken. Consequently every SM2 private key produced by the default `sm2.generateKeyPairHex()` and every signing ephemeral scalar is derived from non-cryptographic sources and is **predictable** by an attacker who can observe a few `Math.random()` outputs and estimate the generation time. This is the library's **default** (no-argument) path; no caller-selected parameter or configuration is required to trigger it. It is reproduced end-to-end against the unmodified real npm packages (`[email protected]` + `[email protected]`); the PoC below runs against the real installed package, not a copy. The defect is still present on the latest published version (0.4.0) and is not covered by any existing `JuneAndGreen/sm-crypto` issue (0 afldl issues exist; the most recent issues are unrelated SM3/HKDF/PBKDF2 feature requests). ## Details `[email protected]` `index.js` — RNG pool initialization (fallback taken in Node): ```js if (rng_pool == null) { rng_pool = new Array(); rng_pptr = 0; var t; if (typeof window !== "undefined" && window.crypto) { // <-- false in Node if (window.crypto.getRandomValues) { /* webcrypto */ } ... } while (rng_pptr < rng_psize) { // <-- fallback path t = Ma
Properties
- ghsa_id
- GHSA-vh45-f885-3848
- severity
- critical
- summary
- sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
- cvss_score
- 9.1
- cve_id
- GHSA-vh45-f885-3848
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-07-24T21:50:45Z
- source_url
- https://github.com/advisories/GHSA-vh45-f885-3848
- ghsa_updated
- 2026-07-24T21:50:46Z
Related Entities (4)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
Explore deeper with Ninja Signal's threat intelligence graph