Insecure Default Initialization of Resource Affecting @haxtheweb/haxcms-nodejs package, versions <11.0.7


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.05% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-HAXTHEWEBHAXCMSNODEJS-10879711
  • published23 Jul 2025
  • disclosed21 Jul 2025
  • creditAsa Reynolds

Introduced: 21 Jul 2025

NewCVE-2025-54127  (opens in a new tab)
CWE-1188  (opens in a new tab)

How to fix?

Upgrade @haxtheweb/haxcms-nodejs to version 11.0.7 or higher.

Overview

@haxtheweb/haxcms-nodejs is a HAXcms nodejs backend

Affected versions of this package are vulnerable to Insecure Default Initialization of Resource due to insecure default settings that disable authentication and authorization checks. An attacker can gain unauthorized access to, modify, or delete all site information by sending unauthenticated requests to the application. This is only exploitable if the default configuration is used without enabling authentication.

CVSS Base Scores

version 4.0
version 3.1