Executive brief
HAX CMS is a microsite management system used to build and maintain web properties. The NodeJS version of HAX CMS has disabled its Content Security Policy (CSP), a critical browser security mechanism that prevents cross-site scripting attacks. If an attacker finds a way to inject malicious code into the application, the lack of CSP would allow arbitrary scripts to run, potentially enabling theft of user session tokens, sensitive data, and account takeover.
Technical details
The vulnerability is a missing security control (CWE-79 related) rather than a direct XSS vulnerability. The Helmet middleware's contentSecurityPolicy directive is explicitly disabled in app.js line 52, leaving the application without browser-level XSS protection. Attack vector is network-based and requires user interaction (victim must visit a malicious page or click a link). An attacker who can inject XSS payloads through any means (stored or reflected XSS, CSRF, etc.) can execute arbitrary JavaScript in the user's browser context, exfiltrate session tokens and sensitive local data, and perform actions on behalf of the user. The fix was available in version 11.0.8, which re-enables CSP in the Helmet configuration.
Affected products
- HAX HAX CMS NodeJS <=11.0.7
Timeline
- 2025-07-21: disclosed: GHSA-59g8-h59f-8hjp published