GHSA-f38f-jvqj-mfg6

Suggest an improvement
Source
https://github.com/advisories/GHSA-f38f-jvqj-mfg6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-f38f-jvqj-mfg6/GHSA-f38f-jvqj-mfg6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f38f-jvqj-mfg6
Aliases
Published
2025-07-21T19:48:58Z
Modified
2025-07-21T22:21:21Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Details

Summary

The NodeJS version of HAX CMS uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks.

Details

If a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication.

insecure-default-configuration-code

Affected Resources

PoC

To reproduce this vulnerability, install HAX CMS NodeJS. The application will load without JWT checks enabled.

Impact

Without security checks in place, an unauthenticated remote attacker could access, modify, and delete all site information.

Database specific
{
    "cwe_ids":  [
        "CWE-1188"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-07-21T19:48:58Z",
    "nvd_published_at":  "2025-07-21T21:15:26Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / @haxtheweb/haxcms-nodejs

Package

Name
@haxtheweb/haxcms-nodejs
View open source insights on deps.dev
Purl
pkg:npm/%40haxtheweb/haxcms-nodejs

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.0.7

Database specific

last_known_affected_version_range
"<= 11.0.6"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-f38f-jvqj-mfg6/GHSA-f38f-jvqj-mfg6.json"