CVE-2025-52650: HCL AION is susceptible to Inline script execution allowed in CSP vulnerability
Published Oct 10, 2025
·Updated
Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0
Affected Software
2 affected components
HCL Aion
hcltech Aion=2.0
Event History
Oct 10, 2025
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52650?
CVE-2025-52650 is classified as a high severity vulnerability due to the risk of inline script execution in HCL AION v2.0.
2
How do I fix CVE-2025-52650?
To remediate CVE-2025-52650, update HCL AION to the latest version that addresses this vulnerability.
3
What types of attacks can CVE-2025-52650 facilitate?
CVE-2025-52650 can facilitate cross-site scripting (XSS) attacks through malicious inline scripts.
4
Which versions of HCL AION are affected by CVE-2025-52650?
CVE-2025-52650 affects HCL AION v2.0 specifically.
5
Is there a workaround for CVE-2025-52650 if I cannot update immediately?
A potential workaround for CVE-2025-52650 includes adjusting content security policies to mitigate the execution of inline scripts.