Executive brief
FUXA is a Node.js-based industrial automation and SCADA visualization platform used to monitor and control critical infrastructure. An authenticated administrator can exploit a flaw in path validation to write malicious scripts to the server, leading to complete system compromise and potential disruption of industrial operations.
Technical details
The vulnerability is a path traversal sanitization bypass (CWE-22, CWE-23, CWE-184) in FUXA's file handling endpoints. The server's single-pass regex sanitization is insufficient to block nested traversal sequences like ....//. An authenticated attacker with administrative privileges can bypass directory restrictions on multiple endpoints (/api/upload, /api/resources/remove, /api/logs) to write arbitrary files into critical directories such as runtime/scripts. When the server reloads these malicious scripts, it leads to Remote Code Execution. The vulnerability is a regression affecting FUXA versions up to 1.2.10 and is patched in version 1.2.11.
Affected products
- FUXA fuxa-server <= 1.2.10
Timeline
- 2026-02-10: disclosed
- 2026-02-10: patched: Patched in FUXA version 1.2.11