CVE-2025-54127: NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
The NodeJS version of HAX CMS uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-54127 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →