Insecure Cookie Handling in HCL AION Leads to Cross-Site Request Risks
CVE-2025-52628

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 February 2026

What is CVE-2025-52628?

HCL AION version 2.0 is affected by a vulnerability that involves the improper handling of cookie attributes, specifically the SameSite attribute. This flaw allows cookies to be transmitted during cross-site requests, which can heighten the risk of cross-site request forgery (CSRF) attacks and similar security threats. Addressing this vulnerability is crucial for maintaining the integrity and security of web applications and preventing unauthorized actions triggered by exploited cookies.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

AION 2.0

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.