A vulnerability was found in ai nanoid up to 3.3.11/5.1.10. It has been classified as critical. Impacted is the function nanoid of the file index.js of the component Fill Pool. This manipulation of the argument size causes integer overflow.

This vulnerability is registered as CVE-2026-73086. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.