npm package report

Is @haxtheweb/haxcms-nodejs safe?

16 known vulnerabilities, worst severity CRITICAL.

cvss
9.3

how bad it is if exploited, out of 10

epss
0.30%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-6c8g-9hfh-pq5h, the advisory selected below

// advisories

GHSA-6c8g-9hfh-pq5h

CRITICALCVE-2026-46395

The hmacBase64() function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated attacker to extract the system’s private signing key and forge arbitrary admin-level JSON Web Tokens (JWTs) allowing them to get full admin access with a single HTTP request.

Affected
>=0, <26.0.0, <= 25.0.0
Fixed in
26.0.0
Weakness
CWE-200
Published
2026-05-19
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 01:46 UTC. The most recent advisory here was published 2026-05-29. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @haxtheweb/haxcms-nodejs safe? npm package security report | CyberXYZ