CVE-2025-52629: Hcltech Aion

Medium severity, CVSS 6.1. EPSS: 0.1% chance of exploitation in the next 30 days.

HCL AION is susceptible to Missing Content-Security-Policy.  An The absence of a CSP header may increase the risk of cross-site scripting and other content injection attacks by allowing unsafe scripts or resources to execute..This issue affects AION: 2.0.

Affected products

Published 2026-02-03. Last modified 2026-06-17.