The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.
{ "binaries": [ { "binary_name": "libjs-mocha", "binary_version": "1.20.1-2" }, { "binary_name": "mocha", "binary_version": "1.20.1-2" } ] }
{ "binaries": [ { "binary_name": "libjs-mocha", "binary_version": "1.20.1-7" }, { "binary_name": "mocha", "binary_version": "1.20.1-7" } ] }
{ "binaries": [ { "binary_name": "mocha", "binary_version": "7.0.1+ds1-2" } ] }
{ "binaries": [ { "binary_name": "node-postcss", "binary_version": "6.0.23-3" } ] }
{ "binaries": [ { "binary_name": "mocha", "binary_version": "9.2.1+ds1+~cs28.3.8-1" } ] }
{ "binaries": [ { "binary_name": "node-postcss", "binary_version": "8.4.6+~cs7.3.21-1" } ] }
{ "binaries": [ { "binary_name": "mocha", "binary_version": "10.4.0+ds1+~cs33.1.8-1" } ] }
{ "binaries": [ { "binary_name": "node-postcss", "binary_version": "8.4.31+~cs8.0.26-1" } ] }
{ "binaries": [ { "binary_name": "mocha", "binary_version": "10.7.2+ds1+~cs33.1.11-2" } ] }
{ "binaries": [ { "binary_name": "node-postcss", "binary_version": "8.4.49+~cs9.2.32-1" } ] }