CVE-2025-69985

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:frangoteam:fuxa:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:00

Type Values Removed Values Added
Summary
  • (es) FUXA 1.2.8 y versiones anteriores contiene una vulnerabilidad de omisión de autenticación que conduce a la ejecución remota de código (RCE). La vulnerabilidad existe en el middleware server/api/jwt-helper.js, que confía indebidamente en el encabezado HTTP 'Referer' para validar solicitudes internas. Un atacante remoto no autenticado puede omitir la autenticación JWT suplantando el encabezado Referer para que coincida con el host del servidor. Si se explota con éxito un atacante podrá acceder al endpoint protegido /api/runscript y ejecutar código Node.js arbitrario en el servidor.

26 Feb 2026, 19:39

Type Values Removed Values Added
First Time Frangoteam
Frangoteam fuxa
CPE cpe:2.3:a:frangoteam:fuxa:*:*:*:*:*:*:*:*
References () https://gist.github.com/lihy10/8cb2dd65ebf1385f12a7e00e25a50d40 - () https://gist.github.com/lihy10/8cb2dd65ebf1385f12a7e00e25a50d40 - Exploit, Third Party Advisory
References () https://github.com/frangoteam/FUXA/blob/master/server/api/jwt-helper.js - () https://github.com/frangoteam/FUXA/blob/master/server/api/jwt-helper.js - Product

25 Feb 2026, 17:25

Type Values Removed Values Added
CWE CWE-288
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

24 Feb 2026, 16:24

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-24 16:24

Updated : 2026-06-17 10:00


NVD link : CVE-2025-69985

Mitre link : CVE-2025-69985

CVE.ORG link : CVE-2025-69985


JSON object : View

Products Affected

frangoteam

  • fuxa
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel