PT-2026-21744 · Fuxa · Fuxa

Published

2026-02-24

·

Updated

2026-04-27

·

CVE-2025-69985

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FUXA versions 1.2.8 and prior
Description FUXA versions 1.2.8 and prior contain an Authentication Bypass issue that can lead to Remote Code Execution (RCE). The issue resides in the server/api/jwt-helper.js middleware, which incorrectly relies on the HTTP "Referer" header for validating internal requests. An unauthenticated remote attacker can bypass JWT authentication by manipulating the Referer header to match the server's host. Successful exploitation grants access to the protected /api/runscript endpoint, enabling the attacker to execute arbitrary Node.js code on the server.
Recommendations Versions prior to 1.2.8 should be updated.

Exploit

Fix

RCE

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2025-69985
GHSA-4R4R-4JP4-WWF9

Affected Products

Fuxa