CVE-2025-54127

Source
https://cve.org/CVERecord?id=CVE-2025-54127
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54127.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54127
Aliases
Published
2025-07-21T20:36:43.580Z
Modified
2026-04-10T05:30:34.860556Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
HAXcms's Insecure Default Configuration Leads to Unauthenticated Access
Details

HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMSDISABLEJWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication. This is fixed in version 11.0.7.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54127.json",
    "cwe_ids": [
        "CWE-1188"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/haxtheweb/haxcms-nodejs

Affected ranges

Type
GIT
Repo
https://github.com/haxtheweb/haxcms-nodejs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "11.0.7"
        }
    ]
}

Affected versions

10.*
10.0.0
v0.*
v0.0.10
v0.0.11
v0.0.12
v0.0.13
v0.0.14
v0.0.15
v0.0.16
v0.0.17
v0.0.18
v0.0.19
v0.0.2
v0.0.3
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v10.*
v10.0.1
v10.0.2
v10.0.3
v10.0.4
v10.0.5
v10.0.6
v11.*
v11.0.0
v11.0.1
v11.0.2
v11.0.3
v11.0.4
v11.0.5
v11.0.6
v9.*
v9.0.0
v9.0.0-alpha.0
v9.0.0-alpha.1
v9.0.1
v9.0.10
v9.0.11
v9.0.12
v9.0.13
v9.0.14
v9.0.15
v9.0.16
v9.0.17
v9.0.18
v9.0.19
v9.0.2
v9.0.20
v9.0.21
v9.0.3
v9.0.4
v9.0.5
v9.0.6
v9.0.7
v9.0.8
v9.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54127.json"