Junglewise Threat Intelligence

CVE-2026-25951: FUXA path traversal sanitization bypass

CVE-2026-25951 · Severity: medium · CVSS 4 · Published 2026-02-10

Technologies: Fuxa-Server. Vendors: npm.

Executive brief

FUXA is a Node.js-based industrial automation and SCADA visualization platform used to monitor and control critical infrastructure. An authenticated administrator can exploit a flaw in path validation to write malicious scripts to the server, leading to complete system compromise and potential disruption of industrial operations.

Technical details

The vulnerability is a path traversal sanitization bypass (CWE-22, CWE-23, CWE-184) in FUXA's file handling endpoints. The server's single-pass regex sanitization is insufficient to block nested traversal sequences like ....//. An authenticated attacker with administrative privileges can bypass directory restrictions on multiple endpoints (/api/upload, /api/resources/remove, /api/logs) to write arbitrary files into critical directories such as runtime/scripts. When the server reloads these malicious scripts, it leads to Remote Code Execution. The vulnerability is a regression affecting FUXA versions up to 1.2.10 and is patched in version 1.2.11.

Affected products

  • FUXA fuxa-server <= 1.2.10

Timeline

  • 2026-02-10: disclosed
  • 2026-02-10: patched: Patched in FUXA version 1.2.11

References

Related threats