Home

Description

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks. The contentSecurityPolicy value is explicitly disabled in the application's Helmet configuration in app.js. This is fixed in version 11.0.8.

PUBLISHED Reserved 2025-07-16 | Published 2025-07-21 | Updated 2025-07-22 | Assigner GitHub_M




HIGH: 7.2CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 11.0.8
affected

References

github.com/...issues/security/advisories/GHSA-59g8-h59f-8hjp

github.com/...ommit/ddb9351c6d6418008d4084a5b17fd6d611bc4e30

cve.org (CVE-2025-54128)

nvd.nist.gov (CVE-2025-54128)

Download JSON