CVE-2025-69983: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2025-69983 is a Remote Code Execution (RCE) vulnerability in FUXA v1.2.7, an open-source web-based SCADA/HMI application developed by frangoteam. The flaw exists in the project import functionality, where user-supplied scripts within imported project files are neither sanitized nor sandboxed, allowing an attacker to upload a malicious project file containing arbitrary system commands. It was published on February 3, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Red Hat CVE, Feedly).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). The vulnerable code resides in server/api/projects/index.js, where the /api/project POST endpoint accepts project data and passes it to runtime.project.setProject() followed by runtime.restart() without adequately validating or sandboxing embedded scripts (FUXA GitHub). An attacker can craft a malicious FUXA project file containing embedded system commands that are executed server-side upon import. The CVSS vector indicates no authentication, no user interaction, and low attack complexity are required, making this trivially exploitable over the network (Red Hat CVE).

Impact

Successful exploitation grants an unauthenticated remote attacker full system compromise on the host running FUXA. This includes unauthorized access to sensitive data (confidentiality impact: HIGH), modification or destruction of system files and project data (integrity impact: HIGH), and potential disruption of SCADA/HMI operations (availability impact: HIGH). Given FUXA's use in industrial control and automation environments, exploitation could have operational technology (OT) consequences beyond the server itself (Red Hat CVE, Feedly).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code has been observed, and there is no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability has been detected by Qualys (detection ID 5007424) and is listed in the GitLab advisory database for the fuxa-server npm package (GitLab Advisory). The EPSS score is approximately 0.058% (0.000580), indicating a currently low but non-negligible probability of exploitation in the near term. No CISA KEV catalog listing or threat actor attribution has been identified at this time.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible FUXA v1.2.7 instances using tools like Shodan (search for fuxa or the default FUXA HTTP port) or by scanning internal OT/ICS networks.
  2. Craft malicious project file: Create a FUXA-compatible project JSON file that embeds malicious script content (e.g., Node.js child_process.exec() calls or OS command strings) within script fields that FUXA evaluates upon project load.
  3. Upload via project import API: Send an HTTP POST request to the /api/project endpoint with the malicious project payload. If the endpoint requires authentication in the target deployment, attempt default or weak credentials first.
  4. Trigger execution: The server calls runtime.project.setProject() with the attacker-controlled data, then invokes runtime.restart(), causing the embedded malicious scripts to be evaluated and executed in the server's Node.js runtime context without sandboxing.
  5. Achieve full system compromise: The executed commands run as the FUXA service account, enabling reverse shell establishment, credential harvesting, lateral movement within the OT/IT network, or persistent backdoor installation (FUXA GitHub, Red Hat CVE).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /api/project from untrusted or external IP addresses; outbound connections from the FUXA server process to unknown external hosts (potential reverse shell or C2 traffic).
  • Logs: FUXA application logs showing project import events (api post project) from unusual sources or at unusual times; Node.js error traces related to script evaluation in project loading routines.
  • Process: Unusual child processes spawned by the FUXA Node.js process (e.g., sh, bash, cmd.exe, powershell, curl, wget, nc); unexpected network listeners created by child processes of the FUXA service.
  • File System: New or modified files in the FUXA installation directory or home directory (e.g., ~/.fuxa/) not associated with normal project saves; presence of web shells, cron jobs, or scheduled tasks created by the FUXA service account.

Mitigation and workarounds

No official vendor patch has been confirmed as available at the time of this report. Recommended interim mitigations include: (1) restricting network access to the FUXA web interface to trusted hosts only using firewall rules; (2) requiring strong authentication for all FUXA API endpoints and disabling unauthenticated access; (3) running FUXA with a least-privilege service account to limit the blast radius of exploitation; (4) sandboxing or containerizing FUXA deployments (e.g., Docker with restricted capabilities); and (5) monitoring for suspicious project import activity and unexpected child process execution. Organizations should monitor the FUXA GitHub repository and vendor communications for patch releases and apply them immediately upon availability (Red Hat CVE, Feedly).

Community reactions

Red Hat has published a CVE tracking page for CVE-2025-69983, indicating awareness within the broader security community (Red Hat CVE). The GitLab advisory database has also catalogued the vulnerability for the fuxa-server npm package (GitLab Advisory). No significant public researcher commentary, vendor statements from frangoteam, or notable media coverage has been identified beyond standard vulnerability database entries at this time.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management