packagist package reportIs lms/routes safe ? 1 known vulnerability, worst severity MODERATE.
// reach 0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
// ai model usage Tracked for PyPI packages. HuggingFace models declare Python dependencies, so packagist packages are not covered.
cvss severity band, no base score published
epss chance of exploitation in 30 days, 62nd percentile of all CVEs
xyz score CyberXYZ composite out of 10
fig. 01 — GHSA-vpw5-grxx-v396, the advisory selected below
// 1 advisories GHSA-vpw5-grxx-v396 When using the CsrfTokenViewHelper the extension discloses the user's session identifier to HTML output without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance Cross Site Scripting in the frontend output. MODE When using the CsrfTokenViewHelper the extension discloses the user's session identifier to HTML output without processing of additional cryptographic hashing algorithms. This vulnerability cannot be exploited directly and occurs in combination with a chained attack - like for instance Cross Site Scripting in the frontend output.
// cvss v3.1 vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N/E:F/RL:O/RC:C
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability None
Exploit maturity F
RL O
RC C Checked 2026-10-04 at 01:15 UTC. The most recent advisory here was published 2021-09-02. Updated continuously from NVD, GHSA, OSV and CNA feeds.
Think a verdict here is wrong? Tell us — we respond within 2 business days. Report an issue with this page