CVE-2026-25938: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-25938 is an authentication bypass vulnerability in FUXA, a web-based Process Visualization (SCADA/HMI/Dashboard) software, that allows unauthenticated remote attackers to execute arbitrary code on the server when the Node-RED plugin is enabled. It affects FUXA versions 1.2.8 through 1.2.10 (npm package fuxa-server), and was disclosed on February 9, 2026, with a patch released the same day in version 1.2.11. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.5 (Critical) (GitHub Advisory, FUXA Security Advisory).

Technical details

The root cause is a combination of missing authentication for a critical function (CWE-306) and authentication bypass by spoofing (CWE-290) in FUXA's Node-RED integration layer. In vulnerable versions, the allowDashboard middleware in server/integrations/node-red/index.js unconditionally permitted requests to the /nodered/flows endpoint — and other Node-RED admin API paths — without verifying any JWT or API key, even when runtime.settings.secureEnabled was set to true. An attacker could send a specially crafted HTTP POST request directly to the /nodered/flows endpoint to submit a malicious Node-RED flow configuration, gaining administrative access to the Node-RED deployment API and achieving arbitrary code execution in the context of the FUXA service process. The fix (commit 5e7679b) introduced proper JWT and API key validation middleware for all Node-RED admin endpoints, and made dangerous modules such as child_process and net opt-in only via a new nodeRedUnsafeModules setting (GitHub Advisory, Patch Commit).

Impact

Successful exploitation grants an unauthenticated remote attacker full administrative control over the Node-RED deployment API, enabling arbitrary code execution in the context of the FUXA service account. This results in high impact to confidentiality, integrity, and availability of the affected system, and may lead to complete server compromise. Because FUXA is commonly deployed in ICS/SCADA environments, exploitation could further expose connected industrial control systems to follow-on actions such as manipulation of physical processes, lateral movement within OT networks, or data exfiltration of sensitive operational data (FUXA Security Advisory, GitHub Advisory).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code has been observed, and there is no confirmed evidence of in-the-wild exploitation (Feedly). However, a Nuclei detection template pull request was submitted to the ProjectDiscovery repository, indicating active community interest in automated scanning for this vulnerability. The EPSS score is approximately 0.097% (35th percentile), reflecting a currently low but non-negligible exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. Qualys has assigned detection ID 5007591 for this CVE (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible FUXA instances running versions 1.2.8–1.2.10 using tools like Shodan, Censys, or Nuclei templates targeting the FUXA web interface (default port 1881). Confirm the Node-RED plugin is enabled by checking for a response from /nodered/ or /nodered/flows.
  2. Probe the vulnerable endpoint: Send an unauthenticated HTTP GET request to /nodered/flows on the target. In vulnerable versions, the server returns the current flow configuration without requiring authentication, confirming exploitability.
  3. Craft a malicious Node-RED flow: Construct a Node-RED flow JSON payload containing an exec node or equivalent that executes an arbitrary OS command (e.g., a reverse shell command). Node-RED's exec node passes input directly to the system shell.
  4. Deploy the malicious flow: Send an HTTP POST request to /nodered/flows with the malicious flow JSON as the request body and Content-Type: application/json. No authentication token or credentials are required in vulnerable versions.
  5. Trigger execution: The deployed flow executes automatically upon deployment. The attacker receives a reverse shell or command output, achieving code execution as the FUXA service account.
  6. Post-exploitation: Use the established foothold to enumerate connected ICS/SCADA devices, exfiltrate operational data, pivot to adjacent OT network segments, or establish persistence (FUXA Security Advisory, Patch Commit).

Indicators of compromise

  • Network: Unauthenticated HTTP GET or POST requests to /nodered/flows, /nodered/flows/state, or /nodered/flows/deploy from external or unexpected IP addresses; outbound connections from the FUXA server process to unknown external hosts (potential reverse shell callbacks).
  • Logs: Web server access logs showing requests to /nodered/flows or other /nodered/ admin endpoints without a valid x-access-token, x-api-key header, or nodered_auth cookie; HTTP 200 responses to unauthenticated POST requests on these endpoints in versions prior to 1.2.11.
  • File System: New or modified flows.json file in the FUXA Node-RED user directory containing unexpected exec, function, or HTTP request nodes with suspicious command strings; unexpected scripts or binaries written to the FUXA installation directory.
  • Process: Unusual child processes spawned by the FUXA Node.js process (e.g., /bin/sh, bash, cmd.exe, curl, wget, python, nc) that are not part of normal FUXA operation; unexpected network listeners created by child processes of the FUXA service.

Mitigation and workarounds

The primary remediation is to upgrade FUXA to version 1.2.11 or later, which introduces proper JWT and API key authentication enforcement on all Node-RED admin endpoints (FUXA Release v1.2.11, Patch Commit). If an immediate upgrade is not possible, disable the Node-RED plugin in FUXA settings if it is not operationally required. Additionally, restrict network access to the FUXA server (default port 1881) using firewall rules and network segmentation, limiting exposure to trusted hosts and networks only, particularly in ICS/SCADA environments (Feedly).

Community reactions

The vulnerability was reported by researcher wodzen and published by the FUXA maintainer unocelli on February 9, 2026, with a same-day patch release. A technical deep-dive and PoC/mitigation walkthrough was published by Undercode Testing, and a dev.to post titled "CVE-2026-25938: FUXA RCE — When the Dashboard Becomes a Command Prompt" highlighted the risk to ICS/SCADA operators. A Nuclei detection template was submitted to ProjectDiscovery's community repository, reflecting active interest from the security research community in automated detection. Red Hat and INCIBE-CERT also tracked the vulnerability in their advisories.

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management