HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis
CVE-2026-46391

8.7HIGH

Key Information:

Vendor

Haxtheweb

Vendor
CVE Published:
5 June 2026

What is CVE-2026-46391?

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis, multiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker can append the matched substrings to an attacker-controlled endpoint and capture authentication. Version 26.0.0 fixes the issue.

Affected Version(s)

@haxtheweb/open-apis >= 9.0.1, < 26.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.