Executive brief
HAX CMS is a content management system used to build and manage microsites. A security flaw allows logged-in users to trick the server into fetching sensitive data from internal networks or the server's own files. This could lead to the exposure of private system files, internal network data, or cloud service credentials, which are then made publicly accessible through the website's file directory.
Technical details
An authenticated Server-Side Request Forgery (SSRF) exists in the 'createSite' endpoint of HAXcms due to insufficient validation of the 'build.files' parameter. The application passes attacker-controlled 'tmp_name' values directly to 'file_get_contents()' when the bulk-import flag is enabled, bypassing standard 'is_uploaded_file()' checks. An attacker with low-level authentication can use this to fetch arbitrary local files (e.g., /etc/passwd), internal network resources, or cloud metadata (e.g., AWS/IMDS). The fetched content is subsequently saved into a web-accessible directory, allowing for easy exfiltration. The vulnerability is addressed in version 26.0.0.
Affected products
- haxtheweb haxcms-nodejs <= 25.0.0
- haxtheweb haxcms-php <= 25.0.0
Timeline
- 2026-05-12: advisory: GitHub Security Advisory published by vendor
- 2026-06-05: disclosed: NVD publication date