Vulnerability Description
HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks. The contentSecurityPolicy value is explicitly disabled in the application's Helmet configuration in app.js. This is fixed in version 11.0.8.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Psu | Haxcms-Nodejs | < 11.0.8 |
Related Weaknesses (CWE)
References
- https://github.com/haxtheweb/haxcms-nodejs/commit/ddb9351c6d6418008d4084a5b17fd6Patch
- https://github.com/haxtheweb/issues/security/advisories/GHSA-59g8-h59f-8hjpThird Party Advisory
FAQ
What is CVE-2025-54128?
CVE-2025-54128 is a vulnerability with a CVSS score of 6.1 (MEDIUM). HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This con...
How severe is CVE-2025-54128?
CVE-2025-54128 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54128?
Check the references section above for vendor advisories and patch information. Affected products include: Psu Haxcms-Nodejs.