criticalCVSS 9.1Vulnerability

GHSA-vh45-f885-3848

## Summary `sm-crypto` (npm package **0.4.0**, the latest release, published 2026-01-20) generates SM2 private keys and signing ephemeral scalars from a single module-wide RNG instance (`src/sm2/utils.js`: `const rng = new SecureRandom()`). `SecureRandom` is jsbn's PRNG, which seeds an **ARC4** stream from `window.crypto.getRandomValues` when available. **In Node.js — sm-crypto's primary runtime — `window` is `undefined`, so the CSPRNG branch is skipped** and the seed pool is instead filled from `Math.random()` (V8 `xorshift128+`, recoverable from a few outputs) plus `new Date().getTime()` (wall clock, attacker-estimable). Node *does* expose Web Crypto as `globalThis.crypto`, but jsbn checks `window.crypto`, not `globalThis.crypto`, so the secure path is never taken. Consequently every SM2 private key produced by the default `sm2.generateKeyPairHex()` and every signing ephemeral scalar is derived from non-cryptographic sources and is **predictable** by an attacker who can observe a few `Math.random()` outputs and estimate the generation time. This is the library's **default** (no-argument) path; no caller-selected parameter or configuration is required to trigger it. It is reproduced end-to-end against the unmodified real npm packages (`[email protected]` + `[email protected]`); the PoC below runs against the real installed package, not a copy. The defect is still present on the latest published version (0.4.0) and is not covered by any existing `JuneAndGreen/sm-crypto` issue (0 afldl issues exist; the most recent issues are unrelated SM3/HKDF/PBKDF2 feature requests). ## Details `[email protected]` `index.js` — RNG pool initialization (fallback taken in Node): ```js if (rng_pool == null) { rng_pool = new Array(); rng_pptr = 0; var t; if (typeof window !== "undefined" && window.crypto) { // <-- false in Node if (window.crypto.getRandomValues) { /* webcrypto */ } ... } while (rng_pptr < rng_psize) { // <-- fallback path t = Ma

Properties

ghsa_id
GHSA-vh45-f885-3848
severity
critical
summary
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
cvss_score
9.1
cve_id
GHSA-vh45-f885-3848
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-07-24T21:50:45Z
source_url
https://github.com/advisories/GHSA-vh45-f885-3848
ghsa_updated
2026-07-24T21:50:46Z

Related Entities (4)

AFFECTS (1)

[Software]npm/sm-crypto

HAS_WEAKNESS (1)

[Weakness]Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/sm-crypto

Explore deeper with Ninja Signal's threat intelligence graph