Junglewise Threat Intelligence

CVE-2025-54127: HAX CMS NodeJS insecure default configuration

CVE-2025-54127 · Severity: medium · CVSS 4 · Published 2025-07-21

Technologies: @haxtheweb/haxcms-nodejs (npm). Vendors: HAX, npm.

Executive brief

HAX CMS is a NodeJS-based content management system used to build and publish websites. The application ships with an insecure default configuration that disables authentication checks (JWT verification), allowing any unauthenticated attacker on the network to read, modify, or delete all website content and data without credentials.

Technical details

The vulnerability is a configuration management flaw (CWE-1188: Insecure Default Initialization with Hard-Coded Network Resource Configuration Data) in which the NodeJS version of HAX CMS defaults to setting 'HAXCMS_DISABLE_JWT_CHECKS' to 'true', disabling session authentication entirely. This insecure default is intended for local development but is exposed if deployed to production without modification. The vulnerability is remotely exploitable over the network with no authentication, privileges, or user interaction required (CVSS vector: AV:N/AC:L/AT:N/PR:N/UI:N). An unauthenticated attacker can access, modify, or delete all site information via API calls. The vulnerability is patched in version 11.0.7; affected versions are up to and including 11.0.6.

Affected products

  • HAX haxcms-nodejs <=11.0.6

Timeline

  • 2025-07-21: disclosed
  • 2025-07-21: patched: Version 11.0.7 patches the vulnerability

References

Related threats