## Summary `sm-crypto` (npm package **0.4.0**, the latest release, published 2026-01-20) generates SM2 private keys and signing ephemeral scalars from a single module-wide RNG instance (`src/sm2/utils.js`: `const rng = new SecureRandom()`). `SecureRandom` is jsbn's PRNG, which seeds an **ARC4** stream from `window.crypto.getRandomValues` when available. **In Node.js — sm-crypto's primary runtime — `window` is `undefined`, so the CSPRNG branch is skipped** and the seed pool is instead filled from `Math.random()` (V8 `xorshift128+`, recoverable from a few outputs) plus `new Date().getTime()` (wall clock, attacker-estimable). Node *does* expose Web Crypto as `globalThis.crypto`, but jsbn checks `window.crypto`, not `globalThis.crypto`, so the secure path is never taken. Consequently every SM2 private key produced by the default `sm2.generateKeyPairHex()` and every signing ephemeral scalar is derived from non-cryptographic sources and is **predictable** by an attacker who can observe a few `Math.random()` outputs and estimate the generation time. This is the library's **default** (no-argument) path; no caller-selected parameter or configuration is required to trigger it. It is reproduced end-to-end against the unmodified real npm packages (`sm-crypto@0.4.0` + `jsbn@1.1.0`); the PoC below runs against the real installed package, not a copy. The defect is still present on the latest published version (0.4.0) and is not covered by any existing `JuneAndGreen/sm-crypto` issue (0 afldl issues exist; the most recent issues are unrelated SM3/HKDF/PBKDF2 feature requests). ## Details `jsbn@1.1.0` `index.js` — RNG pool initialization (fallback taken in Node): ```js if (rng_pool == null) { rng_pool = new Array(); rng_pptr = 0; var t; if (typeof window !== "undefined" && window.crypto) { // <-- false in Node if (window.crypto.getRandomValues) { /* webcrypto */ } ... } while (rng_pptr < rng_psize) { // <-- fallback path t = Math.floor(65536 * Math.random()); // Math.random() rng_pool[rng_pptr++] = t >>> 8; rng_pool[rng_pptr++] = t & 255; } rng_pptr = 0; rng_seed_time(); // + Date.getTime() } ``` `sm-crypto` `src/sm2/utils.js`: ```js const { SecureRandom } = require('jsbn'); const rng = new SecureRandom(); // single module-wide RNG ... function generateKeyPairHex(a, b, c) { const random = a ? new BigInteger(a, b, c) : new BigInteger(n.bitLength(), rng); // uses rng const d = random.mod(n.subtract(BigInteger.ONE)).add(BigInteger.ONE); // private key ... } ``` The default (no-argument) call path uses `rng`, the jsbn ARC4 instance seeded from `Math.random()` + time. The same `rng` feeds the signing ephemeral scalar during SM2 signing. ## PoC The PoC runs against the real installed npm packages. It pins `Math.random` and `Date` **before** `require('sm-crypto')` so jsbn's seed pool is built from controlled inputs. Three independent fresh Node processes then produce the **same** SM2 private key, proving the key is a pure deterministic function of those non-cryptographic sources. It also prints a probe confirming the fallback branch is taken in Node. ### One-line reproducer ```bash WORK=$(mktemp -d) && cd "$WORK" && npm init -y >/dev/null \ && npm install sm-crypto@0.4.0 jsbn@1.1.0 >/dev/null \ && export NODE_PATH="$WORK/node_modules" \ && node poc.js probe && node poc.js deterministic && node poc.js deterministic ``` ### `poc.js` ```js /* * PoC for sm-crypto predictable default RNG in Node.js. * * sm-crypto (npm 0.4.0) generates SM2 private keys / ephemeral scalars using * jsbn's SecureRandom. In a browser jsbn seeds ARC4 from window.crypto, but in * Node.js `window` is undefined so the CSPRNG branch is skipped and the pool is * filled from Math.random() plus new Date().getTime(). Both are * non-cryptographic; the time is attacker-estimable and V8's Math.random is a * recoverable xorshift128+ stream. Consequently SM2 keys produced by the * default path are predictable. * * This PoC proves the key is a deterministic function of those two inputs: we * pin Math.random and the clock to fixed values BEFORE sm-crypto (and therefore * jsbn) is loaded, then generate a keypair. Re-running with the same pinned * values reproduces the exact same private key. */ const MODE = process.argv[2] || 'probe'; // 'probe' | 'deterministic' if (MODE === 'deterministic') { // --- pin entropy sources BEFORE requiring sm-crypto/jsbn --- const fixedTime = 1700000000000; let s = 0x12345678 >>> 0; Math.random = function () { // tiny deterministic LCG standing in for the (already non-crypto) Math.random s = (Math.imul(s, 1103515245) + 12345) >>> 0; return s / 0x100000000; }; const RealDate = globalThis.Date; class FixedDate extends RealDate { constructor(...a) { super(...(a.length === 0 ? [fixedTime] : a)); } } FixedDate.now = () => fixedTime; globalThis.Date = FixedDate; } const sm2 = require('sm-crypto').sm2; const kp = sm2.generateKeyPairHex(); console.log('PRIVATE=' + kp.privateKey); if (MODE === 'probe') { console.log('--- probe ---'); console.log('typeof window =', typeof window, '(undefined in Node => jsbn CSPRNG branch skipped)'); console.log('typeof globalThis.crypto =', typeof globalThis.crypto, '(Node Web Crypto exists but jsbn checks window.crypto, not globalThis.crypto)'); console.log('Math.random sample =', Math.random()); console.log('Date.now() =', Date.now(), '(attacker-estimable, mixed into ARC4 seed)'); } ``` Real captured output: ``` ===== PROBE (real default path, no patching) ===== PRIVATE=6072e45733a4187791ec28ce906fef18c7d33c8529969e1a852833c4349cfc38 --- probe --- typeof window = undefined (undefined in Node => jsbn CSPRNG branch skipped) typeof globalThis.crypto = object (Node Web Crypto exists but jsbn checks window.crypto, not globalThis.crypto) Math.random sample = 0.704452488761137 Date.now() = 1784455686795 (attacker-estimable, mixed into ARC4 seed) ===== DETERMINISTIC (Math.random + Date pinned before require sm-crypto) ===== --- run #1 --- PRIVATE=143268fa0939b4da09eab8c9a2e027a04555b6c433fef4f54fc5edd517c0a6b1 --- run #2 --- PRIVATE=143268fa0939b4da09eab8c9a2e027a04555b6c433fef4f54fc5edd517c0a6b1 ``` The two deterministic runs produce the **identical** SM2 private key, demonstrating the key is a pure function of `Math.random()` + wall-clock time. ## Impact **Private-key recovery / signature forgery of any SM2 keypair generated with the default API in Node.js.** This is the most serious class of defect for a maintained SM2 library: the *default* key-generation path is non-cryptographic on its primary runtime. - **Private-key recovery.** Any SM2 keypair generated with the default API in Node is derived from `Math.random()` + wall-clock time. An attacker who can observe a few `Math.random()` outputs (V8 `xorshift128+` state is recoverable from ~4 observed doubles) and estimate the generation time can reproduce the private key and forge signatures. - **Signing ephemeral reuse / forgery.** The same RNG feeds the ephemeral scalar `k` during SM2 signing; a predictable `k` leaks the private key from a single signature (SM2 is EC-Schnorr-like: `s = (k^-1)(e + d·r) mod n`). - Pre-authentication / no privilege required: anyone who can induce a victim to generate a key or sign a message (the normal API use) is positioned to predict the secret material. ### Suggested fix Seed the RNG from a CSPRNG in Node. The simplest fix in `sm-crypto` is to replace the jsbn ARC4 instance with Web Crypto / `crypto.randomBytes`: ```js // src/sm2/utils.js const nodeCrypto = (typeof require === 'function') ? require('crypto') : null; function csrandBytes(n) { if (nodeCrypto) return nodeCrypto.randomBytes(n); // Node if (globalThis.crypto) { // Web Crypto (browser/Node ≥ 19) const b = new Uint8Array(n); globalThis.crypto.getRandomValues(b); return b; } throw new Error('no CSPRNG available'); } ``` and use it to generate the private key / ephemeral directly, or to reseed the jsbn pool. A separate (upstream) fix belongs in jsbn to check `globalThis.crypto` in addition to `window.crypto`. ### Affected versions - npm `sm-crypto` **0.4.0** (latest, published 2026-01-20). Depends on `jsbn ^1.1.0` (`jsbn@1.1.0`, whose `index.js` RNG is the root cause). - Runtime: Node.js (the primary runtime; in a browser the jsbn CSPRNG branch is taken). ## Credit Reported by the diff/ambidiff security research effort (afldl).
PoC: YellowKey-BitLocker-CVE-2026-45585
YellowKey BitLocker recovery - bitlocker yellowkey, yellowkey bitlocker, CVE-2026-45585, yellowkey github, yellowkey vulnerability, yellowkey CVE, TPM, BitLocker recovery key backup, Windows 10/11, CLI GUI, portable audit tool. Download:🡇
PoC: cve-writeups-and-pocs
CVE-2026-80724 PoC + full write-up — Linux kernel ptp/vmclock read-only mapping becomes writable (VM_MAYWRITE). Discovered, reported & fixed by Abdifatah Suruur (suruurism)
PoC: CVE-2026-79483-FastGPT-NoSQL-Injection
FastGPT Community Edition NoSQL Injection PoC (CVE-2026-79483)
PoC: givewp-cve-2026-82222-rce-lab
Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.
PoC: CVE-2026-19745
Learn how I found my first two CVEs by pure accident.
PoC: cve-2026-23989-opencloud-lab
Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability
poc and yara rules
PoC: CVE-2026-72898
Metabase SQLi
PoC: CVE-2026-19478
GitLab Code injection
PoC: CVE-2026-75604
CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing
PoC: CVE-2026-19632
CVE-2026-19632 - TranslatePress One-Day PoC
PoC: CVE-2026-56705
CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.
PoC: CVE-2026-75604-poc
CVE-2026-75604 Next.js Windows RCE poc
PoC: cve-2026-67363-67364
Balboa form Command Injection POC
PoC: CVE-2026-76581-Detector
Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.
PoC: htb-machine-ringdown
Detailed design & exploitation writeup for Ringdown—an original Debian/Asterisk vulnerable machine featuring CVE-2024-42365 (AMI), PJSIP pre-hash cracking, and Fail2ban POSIX ACL privilege escalation.
PoC: gha-lab-83342297e0
Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection in ci-failure-comment.yml. Snapshot of monkeytypegame/monkeytype @ deeea0f.
PoC: WP2Shell-Scanner
Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)
PoC: phpBB-CVE-2026-48611
Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass
PoC: Project-CVE-2026-45833
CVE-2026-45833 ChromaDB
PoC: CitrixBleedCVE-2026-8452-2025-5777
CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session tokens, extract nsroot hashes, dump secrets, and bypass MFA. Python 3 exploit with full memory parsing.
PoC: CVE-2026-76581
CVE-2026-76581
PoC: drupalgeddon2-cve-lab
Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab
PoC: shellshock-cve-lab
Shellshock CVE-2014-6271 vulnerable CGI lab
PoC: log4shell-cve-lab
Log4Shell CVE-2021-44228 vulnerable lab
PoC: CVE-2026-18741
PoC CVE-2026-18741
PoC: CVE-2026-12513
CVE-2026-12513 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).
PoC: ghostlock-oppo-watch3pro
CVE-2026-43499 on OPPO Watch 3 Pro
PoC: cve-2026-82222-poc
Public PoC for CVE-2026-82222
PoC: zk-xml-probe
Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).
PoC: SOC335-CVE-2024-49138-Investigation
SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.
PoC: papercut-toolkit
#PaperCut CVE-2026-81578 + CVE-2026-82078 Defense Toolkit 2 3 A **defensive** toolkit to check and understand exposure to the chained
PoC: PaperCut-CVE-2026-81578-82078
Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078
PoC: vankyo-s30-bootloader-unlock
Vankyo MatrixPad S30 (Unisoc SC9863A) — Bootloader unlock via CVE-2022-38694 FDL1 method
PoC: CVE-2026-21962-Blog
CVE-2026-21962 Açığı için blog sayfası oluşturdum.
PoC: hdwebmobile-formula-pricing
WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE
PoC: CVE-2026-82286-gpt-crawler-Arbitrary-File-Write
CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS 8.6, CWE-22.
PoC: CVE-2026-24061-payload
A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass
PoC: CVE-2026-66384
CVE-2026-66384 - Draft or TODO
PoC: CVE-2026-33017-PoC-Reverse-Shell
CVE-2026-33017 PoC Reverse Shell
PoC: CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules
CVE-2026-33057 - Mesop Unauthenticated RCE PoC and yara rules
PoC: CVE-2026-10036-speechbrain-rce
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.
PoC: CVE-2025-55182-poc
I know you are probably here from Hack the Box, if so, yes this one actually works.
PoC: Project-CVE-2026-50751
IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features.
PoC: CTT-Enhanced-CVE-2026-46339-Exploit-Engine
A specialized Python framework that executes unauthenticated remote code execution via the 9Router Model Context Protocol (MCP) bridge by deploying a 33-layer temporal phase cascade, Riemann-Hadamard dispersion, and an 11 ns wedge filter to bypass traditional proxy and process-monitoring defenses.
PoC: Zimbra-CVE-2026-73570-Rules
Wazuh Rules for Detection Zimbra (CVE-2026-73570).
PoC: CVE-2022-46169
Cacti 1.2.22 unauthenticated command injection
PoC: CVE-2024-23897
Jenkins CVE-2024-23897 — CSRF-crumb aware PoC
PoC: CVE-2025-10952-ml-logger-AFR
PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3
PoC: CVE-2026-65643
CVE-2026-65643 - Draft or TODO
PoC: cve-2023-23397-detection-lab
Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.
PoC: fastjson-cve
fastjson-cve-2026-16723
PoC: CVE-2026-23751-poc
Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP Remoting)
PoC: CVE-2023-27350-CVE-2023-27351
CVE-2023-27350, CVE-2023-27351 - PaperCut - Draft or TODO
PoC: Project-CVE-2026-33017
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit
PoC: CVE-2026-70463
Testing CVE-2026-70463 by Fyyre
PoC: 2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report
Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server infrastructure, impact across 140,000+ cloud tenants, root-cause findings, and phased mitigation strategies.
PoC: CVE-2026-20131-Post-Incident-Written-Report
Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details root-cause analysis, lateral movement tactics, and emergency containment strategies.
PoC: ghostlock-pfem10
GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes
PoC: htb-labs-connected
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via FreePBX and incron.
PoC: spring-ai-sibling-loop-poc
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)
PoC: mssharepoint-scanner
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.
PoC: weblogic
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)
PoC: CVE-2021-27876-veritas-backup
Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)
PoC: Project-CVE-2026-65351
For educational purposes
PoC: rmg-s9180-fzg1
Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM
PoC: hacktivity-vulns-exploits-lab
Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).
PoC: CVE-2026-55040-Mass-Exploit
CVE-2026-55040
PoC: Project-CVE-2026-75604
A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.
PoC: CVE-2026-18963
CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector
PoC: CVE-2015-3246
CVE-2015-3246
PoC: CVE-2015-5287
CVE-2015-5287
PoC: htb-labs-nexus
Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.
PoC: Cisco-CVE-2026-20303-More
CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313
PoC: CVE-Ubiquiti
CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO
PoC: CVE-2026-18431
CVE-2026-18431 - Draft or TODO
PoC: CVE-2026-8467
CVE-2026-8467 - Draft or TODO
PoC: CVE-2026-50787
Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.
PoC: solarview-ics-vulnerability-analysis
Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)
PoC: CVE-2026-72898-metabase-sqli
Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)
PoC: By-Poloss..-..CVE-2026-18080
Poc CVE-2026-18080
PoC: CVE-2026-63520
POC pre-auth RCE on Sharepoint chain
PoC: f_hid-4.14-backports
Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification records.
PoC: chrome-vuln-scanner
Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.
PoC: CVE-2026-19912-CVE-2026-19913-CVE-2026-19914
CVE-2026-19912, CVE-2026-19913, CVE-2026-19914
PoC: CVE-2026-19632-POC
PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure
PoC: ghostlock-infinix-hot70
Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.
PoC: CVE-2025-2945-pgAdmin-RCE
PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9
PoC: CVE-2026-63072
CVE-2026-63072
PoC: CVE-2026-76904
PostGIS SQL Injection GeoTools
PoC: CVE-2014-085
ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场
PoC: hdwebmobile-photo-video-reviews
WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction
PoC: Exploit-CVE-2026-56705
CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection
PoC: CVE-2026-73570
Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)
PoC: vivo-root-build
vivo/iQOO 提权 so 编译(CVE-2026-43499)
PoC: CVE-2026-72530-TrueConf-Sandbox-Escape-
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.
PoC: CVE-2021-41773-Exploit
CVE-2021-41773 Apache HTTP Server 2.4.49 Path Traversal to RCE Exploit
PoC: cve-2026-60004
CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.
PoC: CVE-2026-68820_Mass_Exploit
CVE-2026-68820 — Mass Exploit Framework Edition.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free