Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-69985

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FUXA是frangoteam开源的一个基于web的过程可视化软件。 FUXA 1.2.8及之前版本存在安全漏洞,该漏洞源于身份验证绕过,server/api/jwt-helper.js中间件不当信任HTTP Referer标头验证内部请求,可能导致远程未认证攻击者通过伪造Referer标头绕过JWT身份验证,进而访问受保护的/api/runscript端点并在服务器上执行任意Node.js代码。

AI Predicted 9.8 Difficulty: Trivial EPSS 5.63% · P92

Public Exploits 1

ExploitDB · 1 EDB-52544 [webapps]
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-69985

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can bypass JWT authentication by spoofing the Referer header to match the server's host. Successful exploitation allows the attacker to access the protected /api/runscript endpoint and execute arbitrary Node.js code on the server.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
FUXA 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
FUXA是frangoteam开源的一个基于web的过程可视化软件。 FUXA 1.2.8及之前版本存在安全漏洞,该漏洞源于身份验证绕过,server/api/jwt-helper.js中间件不当信任HTTP Referer标头验证内部请求,可能导致远程未认证攻击者通过伪造Referer标头绕过JWT身份验证,进而访问受保护的/api/runscript端点并在服务器上执行任意Node.js代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2025-69985

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-69985

登录查看更多情报信息。

Same Patch Batch · n/a · 2026-02-24 · 9 CVEs total

CVE-2026-3102 6.3 MEDIUM exiftool PNG File MacOS.pm SetMacOSTags os command injection
CVE-2026-3067 6.3 MEDIUM HummerRisk Archive Extraction CommandUtils.java extractZip path traversal
CVE-2026-3066 6.3 MEDIUM HummerRisk Cloud Compliance Scanning PlatformUtils.java fixedCommand command injection
CVE-2026-3065 6.3 MEDIUM HummerRisk Cloud Task Dry-run CloudTaskService.java CommandUtils.commonExecCmdWithResult c
CVE-2026-3064 6.3 MEDIUM HummerRisk Cloud Task Scheduler ResourceCreateService.java command injection
CVE-2025-15589 3.8 LOW MuYuCMS Template Management Template.php delete_dir_file path traversal
CVE-2025-67445 TOTOLINK X5000R 安全漏洞
CVE-2025-63409 GCOM EPON 1GE 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-69985

No comments yet


Leave a comment