<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T04:32:08.554577+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351929</id>
    <title>EUVD-2026-351929</title>
    <updated>2026-10-06T04:32:08.611680+00:00</updated>
    <content>EUVD-2026-351929</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351929"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47717</id>
    <title>fkie_cve-2026-47717</title>
    <updated>2026-10-06T04:32:08.611719+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q3w6-q3hc-c5x6</id>
    <title>GHSA-q3w6-q3hc-c5x6 — FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations</title>
    <updated>2026-10-06T04:32:08.611751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: fuxa-server</p>
<p>### Summary</p>
<p>The GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled.</p>
<p>### Details</p>
<p>File: `server/api/projects/index.js`</p>
<p>```javascript
prjApp.get("/api/project", secureFnc, function(req, res) {
    const permission = checkGroupsFnc(req);
    runtime.project.getProject(req.userId, permission).then(result =&gt; {
        if (result) {
            res.json(result);
        }
    });
});
```</p>
<p>The endpoint uses the `secureFnc` middleware, but this middleware calls `verifyToken` in `server/api/jwt-helper.js` which auto-generates a valid guest JWT when no token is provided (line 49-51):</p>
<p>```javascript
if (!token) {
    token = getGuestToken();
}
```</p>
<p>The guest token is signed with the server's secret and passes verification. The handler then calls `getProject` which returns the full project data. The `_filterProjectPermission` function (line 924 of `server/runtime/project/index.js`) filters some UI elements for non-admin users, but it does not remove scripts, devices, alarms, or other sensitive configuration data.</p>
<p>### PoC</p>
<p>**Environment**</p>
<p>- FUXA v1.3.0-2773 (`frangoteam/fuxa:latest`)
- `secureEnabled: true` with a random `secretCode`</p>
<p>**Retrieve full project data without authentication:**</p>
<p>```bash
curl -s http://192.168.32.129:1881/api/project
```</p>
<p>```json
{
  "scripts": [
    {
      "id": "SCRIPT_ID",
      "name": "calculate"
    },
  ]
}
```</p>
<p>No authentication token, API key, or cookie was provided.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q3w6-q3hc-c5x6"/>
  </entry>
</feed>
