Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5r63-q8hg-p8qx | FUXA allows Remote Code Execution (RCE) via the project import functionality. |
Wed, 11 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
ssvc
|
Tue, 10 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:frangoteam:fuxa:1.2.7:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 04 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frangoteam
Frangoteam fuxa |
|
| Vendors & Products |
Frangoteam
Frangoteam fuxa |
Tue, 03 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly sanitize or sandbox user-supplied scripts within imported project files. An attacker can upload a malicious project containing system commands, leading to full system compromise. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-11T17:10:17.573Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69983
Updated: 2026-02-11T17:10:11.197Z
Status : Modified
Published: 2026-02-03T18:16:17.570
Modified: 2026-02-11T18:16:05.980
Link: CVE-2025-69983
No data.
OpenCVE Enrichment
Updated: 2026-02-04T12:17:21Z
Github GHSA