Description
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP “Referer” header to validate internal requests.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.2.8
References
Could your website be exposed too?
SmartScanner can check your website for FUXA has JWT Authentication Bypass via HTTP Referer header spoofing and gives you actionable findings to investigate.
Start a free scanRelated Issues
- SillyTavern has Authentication Bypass via SSO Header Injection - CVE-2026-44649
- Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments - CVE-2025-13877
- Misskey has a login rate limit bypass via spoofed X-Forwarded-For header - CVE-2025-66482
- FUXA has a hardcoded fallback JWT signing secret - CVE-2025-69971


