CVE-2025-40915: Gryphon Mojolicious::plugin::csrf

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Mojolicious::Plugin::CSRF 1.03 for Perl uses a weak random number source for generating CSRF tokens. That version of the module generates tokens as an MD5 of the process id, the current time, and a single call to the built-in rand() function.

Affected products

  • Gryphon Mojolicious::plugin::csrf: version 1.03 only

Published 2025-06-11. Last modified 2026-06-17.