Vulnerabilities/

FUXA contains an insecure default configuration vulnerability

Severity:
High

Description

FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The ‘secureEnabled’ flag is commented out by default, causing the application to initialize with authentication disabled.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
fuxa-server
Anything's wrong? Let us know Last updated on February 10, 2026