PT-2026-5979 · Fuxa · Fuxa
Published
2026-02-03
·
Updated
2026-03-07
·
CVE-2025-69971
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FUXA version 1.2.7
Description
The application uses a hard-coded secret key to sign and verify JWT Tokens. This allows remote attackers to forge valid admin tokens and bypass authentication, potentially gaining full administrative access. The vulnerable component is located in the file
server/api/jwt-helper.js. The JWT Tokens are used for authentication.Recommendations
Replace the hard-coded secret key with a dynamically generated and securely stored key.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fuxa