@frangoteam/fuxa
5 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for @frangoteam/fuxa, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
@frangoteam/fuxa CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 5 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High2
Latest CVEs
The 5 most recently published vulnerabilities affecting @frangoteam/fuxa.
- GHSA-c8m8-3jcr-6rj5FUXA has a hardcoded fallback JWT signing secret—
- CVE-2025-69985FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly tr...9.8
- CVE-2023-31716FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log7.5
- CVE-2023-33831A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.9.8
- CVE-2021-45851A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services, often potentially...7.5
Product grouping is registry-driven, with AI assist and human review. How it works