Junglewise Threat Intelligence

generate-password weak PRNG in random number generation

Severity: info · Published 2019-05-23

Vendors: npm.

Executive brief

The generate-password library is used to create random passwords in applications. A weakness in its random number generation causes certain characters to appear much more frequently than others, making the generated passwords predictable and easier for attackers to guess.

Technical details

The vulnerability is a cryptographic weakness (CWE-338) in the randomNumber function that uses modulo arithmetic on random bytes without addressing bias. Specifically, when calling randomNumber(max) using crypto.randomBytes(1)[0] % max, the distribution is biased if max does not divide 256 evenly—for example, randomNumber(255) makes the value 0 twice as likely as others. This causes certain characters in generated passwords to appear with higher probability, reducing password entropy and making brute-force attacks more feasible. The fix, available in version 1.4.1, discards random values above the highest multiple of the character count that does not exceed 256 to ensure uniform distribution.

Affected products

  • npm generate-password <1.4.1

Timeline

  • 2019-05-23: disclosed
  • 2019-05-23: patched: Fix released in version 1.4.1

References