That may be true, but the more popular FiSH does not, and in my tests of a "default" Mircryption install (with no options tweaked), this was also not the case (it wasn't using CBC by default). I therefore imagine that there are many installs setup in this insecure way.

