Junglewise Threat Intelligence

CVE-2025-69981: FUXA unrestricted file upload in API endpoint

CVE-2025-69981 · Severity: medium · CVSS 4 · Published 2026-02-03

Technologies: fuxa-server (npm), FUXA Team FUXA. Vendors: npm.

Executive brief

FUXA is a web-based process visualization and dashboard software used for industrial control system monitoring and management. An unauthenticated file upload vulnerability in the /api/upload endpoint allows attackers to upload arbitrary files without authentication, potentially overwriting system files or uploading malicious scripts to gain administrative access or execute code on the server.

Technical details

FUXA v1.2.7 contains an unrestricted file upload vulnerability (CWE-434, CWE-306) in the /api/upload API endpoint. The endpoint lacks authentication checks, allowing unauthenticated remote attackers to upload arbitrary files via a direct network request. An attacker can exploit this to overwrite critical system files such as the SQLite user database to escalate privileges to administrator level, or upload malicious scripts to achieve remote code execution. The vulnerability is triggered by sending a POST request to the unprotected endpoint and requires no user interaction or authentication.

Affected products

  • FUXA Team FUXA v1.2.7 and all earlier versions

Timeline

  • 2026-02-03: disclosed: Advisory published
  • 2026-02-04: other: GitHub security team review completed

References

Related threats