PT-2026-21744 · Fuxa · Fuxa
Published
2026-02-24
·
Updated
2026-04-27
·
CVE-2025-69985
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FUXA versions 1.2.8 and prior
Description
FUXA versions 1.2.8 and prior contain an Authentication Bypass issue that can lead to Remote Code Execution (RCE). The issue resides in the
server/api/jwt-helper.js middleware, which incorrectly relies on the HTTP "Referer" header for validating internal requests. An unauthenticated remote attacker can bypass JWT authentication by manipulating the Referer header to match the server's host. Successful exploitation grants access to the protected /api/runscript endpoint, enabling the attacker to execute arbitrary Node.js code on the server.Recommendations
Versions prior to 1.2.8 should be updated.
Exploit
Fix
RCE
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fuxa