- Sources: sm-crypto advisory GHSA-vh45-f885-3848
- Summary: An advisory published 2026-07-24 reports that
sm-crypto 0.4.0 generates SM2 private keys and signing ephemeral scalars from a module-wide jsbn SecureRandom instance. That PRNG seeds an ARC4 stream from window.crypto.getRandomValues when available, but in Node.js window is undefined, so the secure branch is skipped and the seed pool is filled from Math.random(), which is V8 xorshift128+ and recoverable from a few outputs, plus new Date().getTime(). Node exposes Web Crypto as globalThis.crypto, but jsbn checks window.crypto, so the secure path is never taken. The advisory states this is the default no-argument path of sm2.generateKeyPairHex(), that it was reproduced end to end against the unmodified published packages, and that 0.5.0 is the fix. - Why it matters: Every SM2 key and signature nonce produced on the default path is derivable by an attacker who can observe a few
Math.random() outputs and estimate the generation time, so affected keys need replacing rather than just upgrading. - Follow-up: Watch for a CVE assignment and for whether other jsbn-derived libraries carry the same
window.crypto branch on Node.
send feedback on this story