CVE-2025-52624: HCL AION is susceptible to Incorrect Permission Assignment for Critical Resource
A vulnerability Bypass of the script allowlist configuration in HCL AION.
An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.
Other sources
A vulnerability Bypass of the script allowlist configuration in HCL AION.
An Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52624?
CVE-2025-52624 is classified as a high-severity vulnerability due to the risk of unauthorized script execution.
How do I fix CVE-2025-52624?
To fix CVE-2025-52624, ensure that the Content-Security-Policy header is properly configured to restrict unauthorized scripts from executing.
Which software is affected by CVE-2025-52624?
CVE-2025-52624 affects HCL AION version 2.0 and potentially earlier versions.
What type of attacks can CVE-2025-52624 lead to?
CVE-2025-52624 can lead to cross-site scripting (XSS) and other injection-based attacks on web applications.
What is a bypass of the script allowlist configuration in CVE-2025-52624?
A bypass of the script allowlist configuration in CVE-2025-52624 refers to the failure to restrict unauthorized script execution due to improper CSP settings.