CVE-2025-54128: NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting
The NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-54128 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →