CVE-2025-52635: HCL AION is susceptible to Trusted types in scripts not enforced in CSP
Published Oct 10, 2025
·Updated
A
rusted types in scripts not enforced in CSP vulnerability has been identified
in HCL AION.This issue affects AION: 2.0.
Affected Software
2 affected components
HCL AION
hcltech Aion=2.0.0
Event History
Oct 10, 2025
CVE Published
via MITRE·10:21 AM
Data Sourced
via MITRE·10:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52635?
CVE-2025-52635 is classified as a moderate severity vulnerability in HCL AION.
2
How do I fix CVE-2025-52635?
To fix CVE-2025-52635, ensure that proper enforcement of rusted types in scripts is configured according to the latest security best practices.
3
What is the impact of CVE-2025-52635?
CVE-2025-52635 can lead to potential security risks by allowing scripts with untrusted types to bypass Content Security Policy (CSP).
4
What versions of HCL AION are affected by CVE-2025-52635?
CVE-2025-52635 affects HCL AION version 2.0 and potentially earlier versions.
5
Is there a workaround for CVE-2025-52635?
Currently, there are no confirmed workarounds for CVE-2025-52635; applying the latest updates from the vendor is recommended.