Executive brief
HAX CMS is a NodeJS-based content management system used to build and publish websites. The application ships with an insecure default configuration that disables authentication checks (JWT verification), allowing any unauthenticated attacker on the network to read, modify, or delete all website content and data without credentials.
Technical details
The vulnerability is a configuration management flaw (CWE-1188: Insecure Default Initialization with Hard-Coded Network Resource Configuration Data) in which the NodeJS version of HAX CMS defaults to setting 'HAXCMS_DISABLE_JWT_CHECKS' to 'true', disabling session authentication entirely. This insecure default is intended for local development but is exposed if deployed to production without modification. The vulnerability is remotely exploitable over the network with no authentication, privileges, or user interaction required (CVSS vector: AV:N/AC:L/AT:N/PR:N/UI:N). An unauthenticated attacker can access, modify, or delete all site information via API calls. The vulnerability is patched in version 11.0.7; affected versions are up to and including 11.0.6.
Affected products
- HAX haxcms-nodejs <=11.0.6
Timeline
- 2025-07-21: disclosed
- 2025-07-21: patched: Version 11.0.7 patches the vulnerability