{"id":"GHSA-f38f-jvqj-mfg6","summary":"NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access","details":"### Summary\nThe NodeJS version of HAX CMS uses an insecure default configuration designed for local\ndevelopment. The default configuration does not perform authorization or authentication checks.\n\n### Details\nIf a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication. \n\n![insecure-default-configuration-code](https://github.com/user-attachments/assets/af58b08a-8a26-4ef5-8deb-e6e9d4efefaa)\n\n#### Affected Resources\n- [package.json:13](https://github.com/haxtheweb/haxcms-nodejs/blob/a4d2f18341ff63ad2d97c35f9fc21af8b965248b/package.json#L13)\n\n### PoC\nTo reproduce this vulnerability, [install](https://github.com/haxtheweb/haxcms-nodejs) HAX CMS NodeJS. The application will load without JWT checks enabled. \n\n### Impact\nWithout security checks in place, an unauthenticated remote attacker could access, modify, and delete all site information.","aliases":["CVE-2025-54127"],"modified":"2025-07-21T22:21:21Z","published":"2025-07-21T19:48:58Z","database_specific":{"nvd_published_at":"2025-07-21T21:15:26Z","cwe_ids":["CWE-1188"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2025-07-21T19:48:58Z"},"references":[{"type":"WEB","url":"https://github.com/haxtheweb/issues/security/advisories/GHSA-f38f-jvqj-mfg6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54127"},{"type":"PACKAGE","url":"https://github.com/haxtheweb/haxcms-nodejs"}],"affected":[{"package":{"name":"@haxtheweb/haxcms-nodejs","ecosystem":"npm","purl":"pkg:npm/%40haxtheweb/haxcms-nodejs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.0.7"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 11.0.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/07/GHSA-f38f-jvqj-mfg6/GHSA-f38f-jvqj-mfg6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}