{"id":"CVE-2025-54127","aliases":["GHSA-f38f-jvqj-mfg6"],"url":"https://o3.security/vulnerability/CVE-2025-54127","summary":"HAXcms's Insecure Default Configuration Leads to Unauthenticated Access","details":"### Summary\nThe NodeJS version of HAX CMS uses an insecure default configuration designed for local\ndevelopment. The default configuration does not perform authorization or authentication checks.\n\n### Details\nIf a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication. \n\n![insecure-default-configuration-code](https://github.com/user-attachments/assets/af58b08a-8a26-4ef5-8deb-e6e9d4efefaa)\n\n#### Affected Resources\n- [package.json:13](https://github.com/haxtheweb/haxcms-nodejs/blob/a4d2f18341ff63ad2d97c35f9fc21af8b965248b/package.json#L13)\n\n### PoC\nTo reproduce this vulnerability, [install](https://github.com/haxtheweb/haxcms-nodejs) HAX CMS NodeJS. The application will load without JWT checks enabled. \n\n### Impact\nWithout security checks in place, an unauthenticated remote attacker could access, modify, and delete all site information.","published":"2025-07-21T20:36:43.580Z","modified":"2026-08-12T03:51:20.323461142Z","cvss":null,"epss":{"score":0.00403,"percentile":0.33231,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@haxtheweb/haxcms-nodejs","fixedVersion":"11.0.7"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54127.json"},{"type":"ADVISORY","url":"https://github.com/haxtheweb/issues/security/advisories/GHSA-f38f-jvqj-mfg6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54127"},{"type":"PACKAGE","url":"https://github.com/haxtheweb/haxcms-nodejs"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.323461142Z"}}