
CVE-2025-52629 HCL AION is susceptible to Missing Content-Security-Policy. An The absence of a CSP header may increase the risk of cross-site scripting and other content injection… https://www.cve.org/CVERecord?id=CVE-2025-52629
Post summary
The post announces that HCL AION is vulnerable because it lacks a CSP header, which could allow cross‑site scripting or content injection, but it provides no PoC, exploit, or patch information.
