CVE-2025-62318: HCL AION is affected by multiple security vulnerabilities.
Published Aug 13, 2026
·Updated
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
Event History
Aug 13, 2026
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62318?
The severity of CVE-2025-62318 is classified as low with a score of 3.7.
2
How do I fix CVE-2025-62318?
To fix CVE-2025-62318, implement proper content security policies to limit the exposure of JavaScript responses.
3
What are the potential impacts of CVE-2025-62318?
CVE-2025-62318 could allow an attacker to capture sensitive information through JavaScript hijacking.
4
Is CVE-2025-62318 related to cross-site request forgery?
Yes, CVE-2025-62318 is categorized under CSRF vulnerabilities.
5
When was CVE-2025-62318 published?
CVE-2025-62318 was published on August 13, 2026.