{"id":"CVE-2025-54128","aliases":["GHSA-59g8-h59f-8hjp"],"url":"https://o3.security/vulnerability/CVE-2025-54128","summary":"HAX CMS NodeJs's Disabled Content Security Policy Enables Cross-Site Scripting","details":"HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks. The contentSecurityPolicy value is explicitly disabled in the application's Helmet configuration in app.js. This is fixed in version 11.0.8.","published":"2025-07-21T20:46:31.660Z","modified":"2026-08-12T03:51:17.914421227Z","cvss":null,"epss":{"score":0.00202,"percentile":0.10131,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@haxtheweb/haxcms-nodejs","fixedVersion":"11.0.8"}],"fix":{"url":"https://github.com/haxtheweb/haxcms-nodejs/commit/ddb9351c6d6418008d4084a5b17fd6d611bc4e30","label":"haxtheweb/haxcms-nodejs@ddb9351"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54128.json"},{"type":"ADVISORY","url":"https://github.com/haxtheweb/issues/security/advisories/GHSA-59g8-h59f-8hjp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54128"},{"type":"FIX","url":"https://github.com/haxtheweb/haxcms-nodejs/commit/ddb9351c6d6418008d4084a5b17fd6d611bc4e30"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:17.914421227Z"}}