FUXA contains an Unrestricted File Upload vulnerability
High severity
GitHub Reviewed
Published
Feb 3, 2026
to the GitHub Advisory Database
•
Updated Feb 10, 2026
Description
Published by the National Vulnerability Database
Feb 3, 2026
Published to the GitHub Advisory Database
Feb 3, 2026
Reviewed
Feb 4, 2026
Last updated
Feb 10, 2026
FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the
/api/uploadAPI endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain administrative access, or to upload malicious scripts to execute arbitrary code.References