Nanoid is a minimal JavaScript library providing unique identifier generation, with a narrow but widely embedded footprint across JavaScript applications and packages. Its observed vulnerabilities center on the nanoid product itself and involve incorrect type conversion and casting logic, the kind of flaw that can arise in cryptographic or encoding-critical code paths. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nanoid Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23566MEDIUM The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated. | Jan 14, 2022 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nanoid Project.
Media articles that mention a CVE ID that affects a product developed by Nanoid Project — matched by CVE ID, not by vendor name.