PT-2026-41978 · Npm+1 · @Haxtheweb/Haxcms-Nodejs+3

CVE-2026-46496

·

Published

2026-05-19

·

Updated

2026-06-06

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions HAX CMS versions prior to 26.0.0
Description A stored cross-site scripting (XSS) issue exists due to improper sanitization of the <video-player> component. The application fails to validate or sanitize user-supplied input in the source and source-data attributes, allowing the use of javascript: URIs. When a victim views the affected page, the arbitrary JavaScript is executed in their browser context, which can lead to the theft of sensitive data such as JWT (JSON Web Tokens) authentication tokens, session hijacking, and full account takeover. If an administrator views the malicious page, it could result in a full compromise of the CMS.
Recommendations Update to version 26.0.0. As a temporary workaround, restrict the use of the source and source-data attributes within the <video-player> component to minimize the risk of exploitation.

Exploit

Fix

Improper Encoding or Escaping of Output

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46496
GHSA-2M6P-HM3W-6JM3

Affected Products

@Haxtheweb/Haxcms-Nodejs
@Haxtheweb/Video-Player
Haxcms-Nodejs
Video-Player