๐Ÿ” CVE Alert

CVE-2026-67443

UNKNOWN 0.0

FUXA: Unauthenticated guest JWT bypasses Node-RED secure-mode authorization gate (Remote Script Execution)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. When nodeRedEnabled is true, secureEnabled is true, and nodeRedAuthMode is secure, a remote unauthenticated attacker can obtain a signed guest token from POST /api/heartbeat and use it to access the RED.httpAdmin editor and flow deployment API. Because the Node-RED configuration has no second adminAuth gate, the attacker can deploy function nodes or invoke fuxa.runScript and runtime.scriptsMgr.runScript, gaining control of FUXA project data, configuration, scripts, filesystem-capable runtime helpers, and potentially operating-system commands when nodeRedUnsafeModules is enabled. This issue is fixed in version 1.3.3.

CWE CWE-862
Vendor frangoteam
Product fuxa
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for frangoteam fuxa

Be the first to know when new unknown vulnerabilities affecting frangoteam fuxa are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

frangoteam / FUXA
< 1.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/frangoteam/FUXA/security/advisories/GHSA-5h5x-9h7x-23f4 github.com: https://github.com/frangoteam/FUXA/pull/2393 github.com: https://github.com/frangoteam/FUXA/commit/e0b553cddb55613b890341270eb17eb586f8cab5 github.com: https://github.com/frangoteam/FUXA/releases/tag/v1.3.3