Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-69985

Опубликовано: 24 фев. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:frangoteam:fuxa:*:*:*:*:*:*:*:*
Версия до 1.2.8 (включая)

EPSS

Процентиль: 93%
0.05633
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-288

Связанные уязвимости

CVSS3: 9.8
github
7 месяцев назад

FUXA has JWT Authentication Bypass via HTTP Referer header spoofing

EPSS

Процентиль: 93%
0.05633
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-288