GHSA-4r4r-4jp4-wwf9

Suggest an improvement
Source
https://github.com/advisories/GHSA-4r4r-4jp4-wwf9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-4r4r-4jp4-wwf9/GHSA-4r4r-4jp4-wwf9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4r4r-4jp4-wwf9
Aliases
Published
2026-02-24T18:31:02Z
Modified
2026-02-26T16:11:20Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
FUXA has JWT Authentication Bypass via HTTP Referer header spoofing
Details

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.

Database specific
{
    "cwe_ids":  [
        "CWE-288"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-26T15:45:40Z",
    "nvd_published_at":  "2026-02-24T16:24:07Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / @frangoteam/fuxa

Package

Name
@frangoteam/fuxa
View open source insights on deps.dev
Purl
pkg:npm/%40frangoteam/fuxa

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.2.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-4r4r-4jp4-wwf9/GHSA-4r4r-4jp4-wwf9.json"