Junglewise Threat Intelligence

CVE-2025-54134: HAX CMS NodeJS improper error handling denial of service

CVE-2025-54134 · Severity: medium · CVSS 4 · Published 2025-07-21

Technologies: @haxtheweb/haxcms-nodejs (npm). Vendors: HAX, npm.

Executive brief

HAX CMS is a content management system used to build and host websites. An authenticated attacker can crash the application's backend server by sending specially-crafted requests to file management endpoints without required parameters, rendering the system and all hosted websites unavailable to legitimate users.

Technical details

This vulnerability exists in the listFiles and saveFile API endpoints, which fail to properly handle exceptions when required URL parameters are missing or malformed. An authenticated attacker can trigger an ERR_INVALID_ARG_TYPE exception by sending requests without the expected parameters, causing the Node.js backend process to crash. The vulnerability requires low-level authentication credentials but no user interaction. Exploitation results in complete denial of service for all users of the backend system and any websites it hosts. A patch is available in version 11.0.9 and later.

Affected products

  • HAX CMS NodeJS <=11.0.8

Timeline

  • 2025-07-21: disclosed

References

Related threats