Executive brief
FUXA is a web-based industrial control and dashboard platform used to visualize and manage industrial processes. A security flaw allows an unauthenticated attacker to bypass security checks and execute arbitrary commands on the server. This could lead to a total takeover of the system, unauthorized access to industrial equipment, and theft of sensitive operational data.
Technical details
An unauthenticated remote code execution (RCE) vulnerability exists in FUXA version 1.3.0 due to an authorization bypass in the script execution engine. The `POST /api/runscript` endpoint validates permissions against a stored script's ID; however, if the `test: true` flag is included in the request, the server executes attacker-supplied code instead of the stored script. Because the middleware automatically assigns a guest token to unauthenticated requests and scripts without explicit permissions default to being accessible, an attacker can leverage a known script ID (obtainable via information disclosure) to execute arbitrary Node.js code. The vulnerability allows full access to the underlying operating system via the `child_process` module. This issue is resolved in version 1.3.1.
Affected products
- frangoteam FUXA 1.3.0
Timeline
- 2026-03-19: patched: Fix merged into master branch
- 2026-04-09: other: Version 1.3.1 released
- 2026-05-19: advisory: GitHub Security Advisory published
- 2026-07-21: disclosed: CVE published to NVD