Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/@frangoteam/fuxa — 6 CVEs · VulnScope
pkg:npm/
@frangoteam/fuxa
6 total CVEs
CRITICAL
2
HIGH
3
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2025-69985
FUXA has JWT Authentication Bypass via HTTP Referer header spoofing
from 0, <= 1.2.8
CRITICAL
9.8
CVE-2023-33831
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA
from 0, <= 1.1.13
HIGH
8.1
CVE-2025-69971
FUXA has a hardcoded fallback JWT signing secret
from 0, < 1.3.0
HIGH
7.5
FUXA vulnerable to Local File Inclusion
from 0, <= 1.1.12
HIGH
7.5
Server-Side Request Forgery in FUXA
from 0, <= 1.1.3
—
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
>= 1.2.11, < 1.3.1
CVE-2023-31716
CVE-2021-45851
CVE-2026-43945