/Vulnerability Library

FUXA <= 1.2.7 - Hardcoded JWT Secret Authentication Bypass

CVE-2025-69971
Verified

Description

FUXA v1.2.7 contains a hardcoded credentials vulnerability caused by use of a hard-coded secret key in server/api/jwt-helper.js, letting remote attackers forge admin tokens and bypass authentication, exploit requires no special conditions.

Severity

Critical

CVSS Score

9.8

Exploit Probability

2%

Affected Product

fuxa

Published Date

February 15, 2026

Template Author

trader642

CVE-2025-69971.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-69971
CWE ID:
cwe-321

References

https://github.com/frangoteam/FUXA/security/advisories/GHSA-32cc-x95p-fxcghttps://nvd.nist.gov/vuln/detail/CVE-2025-69971https://github.com/frangoteam/FUXA/blob/master/server/api/jwt-helper.js

Remediation Steps

Update to the latest version that removes hard-coded credentials.