Vulnerabilities/

FUXA contains an Unrestricted File Upload vulnerability

Severity:
High

Description

FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the /api/upload API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
fuxa-server
Anything's wrong? Let us know Last updated on February 10, 2026