3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether crypto-js is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.1
CVE-2023-46233
crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
CRITICAL 9.0
CVE-2026-71851
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
MEDIUM 5.3
CVE-2020-36732
crypto-js uses insecure random numbers
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes