{"id":"CVE-2019-25061","aliases":["GHSA-ggfx-h9xj-5v9c"],"url":"https://o3.security/vulnerability/CVE-2019-25061","summary":"Insecure PRNG use in random_password_generator","details":"The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.","published":"2022-05-18T11:15:10.670Z","modified":"2026-07-08T16:27:56.008839Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"random_password_generator","fixedVersion":null}],"fix":{"url":"https://github.com/bvsatyaram/random_password_generator/pull/1","label":"bvsatyaram/random_password_generator#1"},"references":[{"type":"ADVISORY","url":"https://github.com/bvsatyaram/random_password_generator/blob/2855e8d7d8803dbb580ddd6cf13846394eb4530e/lib/random_password_generator.rb#L23"},{"type":"ADVISORY","url":"https://ruby-doc.org/core-3.1.2/Random.html"},{"type":"REPORT","url":"https://github.com/bvsatyaram/random_password_generator/pull/1"},{"type":"EVIDENCE","url":"https://stackoverflow.com/questions/42170239/security-of-rand-in-ruby-compared-to-other-methods/42170560"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:27:56.008839Z"}}