CRITICAL🇵🇱 Wersja polska

CVE-2025-54127

CVSS 9.3v4.0pub. 2025-07-21upd. 2025-07-30

HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication. This is fixed in version 11.0.7.

🤖 AI Analysis
How it works

The default configuration of haxcms-nodejs sets the 'HAXCMS_DISABLE_JWT_CHECKS' variable to 'true', which is a design intended solely for local environments. If an administrator deploys the application without changing these settings, all authorization and authentication mechanisms based on JWT are completely bypassed. As a result, any network user can communicate with the HAXcms server as if they were a logged-in and authorized user.

Impact

An attacker without any credentials can gain unauthorized access to the entire HAXcms instance, potentially reading, modifying, or deleting data and taking control of content management.

Mitigation & patch

Update haxcms-nodejs to version 11.0.7, where the issue has been fixed. Until the update is applied, ensure that the 'HAXCMS_DISABLE_JWT_CHECKS' variable is set to 'false' in the production configuration.

Who is affected

HAXcms with Node.js backend (haxcms-nodejs) in versions 11.0.6 and earlier, deployed with default configuration without manually disabling 'HAXCMS_DISABLE_JWT_CHECKS'.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Psu Haxcms Node.js

    APP
    Psu
    < 11.0.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-22704HIGH8.0same product

HAX CMS helps manage microsite universe with PHP or NodeJs backends. In versions 11.0.6 to before 25.0.0, HAX ...

CVE-2025-54378HIGH8.3same product

HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends. In versions 11.0.13 and belo...

CVE-2025-54137HIGH7.3same product

HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and belo...

CVE-2025-54134HIGH7.1same product

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and b...

CVE-2025-54128HIGH7.2same product

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and b...