Insecure Default Configuration in HAXcms with NodeJS Backend
CVE-2025-54127

9.3CRITICAL

Key Information:

Vendor

Haxtheweb

Status
Vendor
CVE Published:
21 July 2025

What is CVE-2025-54127?

The HAXcms with a NodeJS backend is affected by an insecure default configuration that allows users to start the server in any HAXsite without proper authorization or authentication checks. The default setting for HAXcms versions 11.0.6 and earlier allows for 'HAXCMS_DISABLE_JWT_CHECKS' to be enabled, leading to configurations that lack session authentication. This vulnerability can be exploited if the software is deployed without proper modifications, potentially exposing sensitive data and functionalities. The issue has been resolved in version 11.0.7.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

issues < 11.0.7

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.