Bypass of Script Allowlist in HCL AION
CVE-2025-52624

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 October 2025

What is CVE-2025-52624?

The vulnerability in HCL AION arises from an improperly configured Content-Security-Policy header, which may permit unauthorized scripts to be executed. This misconfiguration heightens the vulnerability to cross-site scripting (XSS) and other injection-based attacks, potentially leading to unauthorized data access or manipulation. Specifically, this issue affects version 2.0 of HCL AION, emphasizing the critical importance of proper security configuration in safeguarding web applications.

Affected Version(s)

AION 2.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52624 : Bypass of Script Allowlist in HCL AION