Junglewise Threat Intelligence

CVE-2026-73567: sm-crypto predictable SM2 key generation in Node.js

CVE-2026-73567 · Severity: low · CVSS 3.1 · Published 2026-07-24

Technologies: sm-crypto (npm). Vendors: npm.

Executive brief

sm-crypto is a Node.js library for generating SM2 cryptographic keys and digital signatures used in Chinese cryptography standards. The library uses non-cryptographic random number generation (Math.random and wall clock time) to create private keys and signing values by default, making them predictable to attackers. This allows an attacker with knowledge of the system time and a few random outputs to forge signatures or decrypt communications protected by sm-crypto-generated keys.

Technical details

The vulnerability is a weak RNG (random number generator) issue in sm-crypto's default key generation path. The library uses jsbn's SecureRandom class, which attempts to seed from window.crypto.getRandomValues in browser environments. However, in Node.js, the `window` object is undefined, causing the CSPRNG branch to be skipped and the seed pool to be filled from V8's Math.random (xorshift128+, recoverable from outputs) plus new Date().getTime() (wall clock, attacker-estimable). Although Node.js exposes Web Crypto via globalThis.crypto, jsbn checks only window.crypto, so the secure path is never taken. The vulnerability affects the default no-argument call to sm2.generateKeyPairHex() and signing ephemeral scalars; no user configuration is required to trigger it. A proof-of-concept demonstrates that identical private keys are generated when Math.random and Date are pinned to fixed values across multiple process invocations. The issue is present in all versions up to 0.4.0; version 0.5.3 or later contains a patch.

Affected products

  • JuneAndGreen sm-crypto <0.5.3

Timeline

  • 2026-07-24: disclosed
  • 2026-07-23: patched: Patched version 0.5.3 released

References

Related threats