Vulnerabilities/

FUXA has JWT Authentication Bypass via HTTP Referer header spoofing

Severity:
High

Description

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP “Referer” header to validate internal requests.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@frangoteam/fuxa
Anything's wrong? Let us know Last updated on February 26, 2026