> Experimental React Flight bindings for DOM using Webpack.
> Use it at your own risk.
311,955 weekly downloads though :-|
Beyond that, I think there is good reason to believe that the number is inflated due to automated downloads from things like CI pipelines, where hundreds or thousands of downloads might only represent a single instance in the wild.
The above could be seen as spin too, how could cvss be more accurate so you’d feel better?
While scores are a good way to bring this stuff to people's attention, I wouldn't use them to enforce business processes. There's a good chance your code isn't even affected by this CVE even if your security scanners all go full red alert on this bug.
Surprised there isn’t more talk about a solution like this or something and more downplaying CVSS.
Downplaying CVSS alone can smell a little like PR talk even however unintentional.