CVE Vulnerabilities

CVE-2025-69985

Authentication Bypass Using an Alternate Path or Channel

Published: Feb 24, 2026 | Modified: Feb 26, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP Referer header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the servers host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
FuxaFrangoteam*1.2.8 (including)

Potential Mitigations

References