Description
Pre-auth RCE in FUXA via Logic Bypass
Summary
A Critical vulnerability chain exists in FUXA (v.1.3.0-2706) that allows an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state (Secure Mode Enabled and Node-RED Secure Auth Enabled).
Recommendation
Update the @frangoteam/fuxa package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.2.11, < 1.3.1
- Patched version(s): 1.3.1
References
Could your website be exposed too?
SmartScanner can check your website for FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection - CVE-2026-31975
- i18next-locize-backend has URL Injection via Unsanitized Path Parameters - CVE-2026-41885
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards - CVE-2026-4923
- fast-uri vulnerable to path traversal via percent-encoded dot segments - CVE-2026-6321


