Javascript Predictable Iv Nonce Source
Description
This vulnerability detector identifies the use of predictable or weak initialization vectors (IVs) and nonces in JavaScript cryptographic operations. Using predictable IVs/nonces can compromise the security of encryption algorithms by making encrypted data susceptible to pattern analysis and cryptographic attacks.
Detection Strategy
• The detector scans JavaScript source code for cryptographic function calls that use initialization vectors or nonces
• It identifies cases where IVs or nonces are generated using predictable sources such as hardcoded values, simple incremental counters, or weak random number generators
• A vulnerability is reported when cryptographic operations use predictable or static IV/nonce values instead of cryptographically secure random values
• The detection focuses on encryption functions, cipher initialization, and other cryptographic operations that require secure randomness for IVs or nonces
Vulnerable code example
const crypto = require('crypto');
function encryptData(key, data) {
// VULNERABLE: IV derived from Date.now() is predictable to attackers
const cipher = crypto.createCipheriv(
'aes-256-cbc',
key,
Buffer.from(Date.now().toString().padStart(16, '0'))...✅ Secure code example
const crypto = require('crypto');
function encryptData(key, data) {
// SAFE: IV generated from crypto.randomBytes() is unpredictable
const iv = crypto.randomBytes(16);
const cipher = crypto.createCipheriv('aes-256-cbc', key, iv);
const encrypted = Buffer.concat([cipher.update(data), cipher.final()]);
// Return IV prepended to encrypted data for decryption...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.