PT-2026-41978 · Npm+1 · @Haxtheweb/Haxcms-Nodejs+3
CVE-2026-46496
·
Published
2026-05-19
·
Updated
2026-06-06
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
HAX CMS versions prior to 26.0.0
Description
A stored cross-site scripting (XSS) issue exists due to improper sanitization of the
<video-player> component. The application fails to validate or sanitize user-supplied input in the source and source-data attributes, allowing the use of javascript: URIs. When a victim views the affected page, the arbitrary JavaScript is executed in their browser context, which can lead to the theft of sensitive data such as JWT (JSON Web Tokens) authentication tokens, session hijacking, and full account takeover. If an administrator views the malicious page, it could result in a full compromise of the CMS.Recommendations
Update to version 26.0.0.
As a temporary workaround, restrict the use of the
source and source-data attributes within the <video-player> component to minimize the risk of exploitation.Exploit
Fix
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Haxtheweb/Haxcms-Nodejs
@Haxtheweb/Video-Player
Haxcms-Nodejs
Video-Player