{"id":"GHSA-r9g5-7q8j-958c","summary":"FUXA provides guest and invalid-token access to protected read APIs in secure mode","details":"### Summary\n\n  When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs.\n\n  ### Details\n\n  In secure mode, requests with no token or an explicitly invalid token were still able to access protected read endpoints.\n\n  Confirmed behavior:\n\n  - guest `GET /api/project` returned `200 OK`\n  - invalid-token requests to `/api/project` also returned successful responses containing project data\n  - guest and invalid-token requests also returned `200 OK` on:\n    - `/api/alarms`\n    - `/api/scheduler`\n\n  Relevant code paths identified during analysis:\n\n  - `server/api/jwt-helper.js`\n    - `verifyToken()` converts missing-token or invalid-token states into guest context instead of rejecting the request\n  - `server/api/projects/index.js`\n  - `server/api/alarms/index.js`\n  - `server/api/scheduler/index.js`\n\n  These handlers accepted the guest context and returned sensitive data in secure mode.\n\n  ### PoC\n\n  Tested only against isolated local lab instances under the original tester's control. No production, customer, shared, or third-party systems were involved.\n\n  Reproduction:\n\n  1. Start FUXA `1.3.0-2773`.\n  2. Set `secureEnabled=true`.\n  3. Send unauthenticated requests to:\n     - `GET /api/project`\n     - `GET /api/alarms`\n     - `GET /api/scheduler?id=test`\n  4. Observe `200 OK` responses.\n  5. Send the same requests with an explicitly invalid `x-access-token` value.\n  6. Observe the same successful responses.\n\n The exact HTTP requests and local PoC script used for confirmation can be provided upon request.\n\n  ### Impact\n\n  This is an authentication/authorization weakness in secure mode.\n\n  Impact includes:\n\n - project metadata disclosure\n - alarms disclosure\n - scheduler information disclosure\n - assistance in reconnaissance/follow-on attacks\n\n  Operators who believe secure mode protects these APIs are impacted.","aliases":["CVE-2026-47718"],"modified":"2026-05-28T20:56:25.620310Z","published":"2026-05-28T20:33:11Z","database_specific":{"github_reviewed_at":"2026-05-28T20:33:11Z","nvd_published_at":null,"cwe_ids":["CWE-287","CWE-862"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/frangoteam/FUXA/security/advisories/GHSA-r9g5-7q8j-958c"},{"type":"PACKAGE","url":"https://github.com/frangoteam/FUXA"},{"type":"WEB","url":"https://github.com/frangoteam/FUXA/releases/tag/v1.3.1"}],"affected":[{"package":{"name":"fuxa-server","ecosystem":"npm","purl":"pkg:npm/fuxa-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.3.0-2773"},{"fixed":"1.3.1"}]}],"versions":["1.3.0-2773"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-r9g5-7q8j-958c/GHSA-r9g5-7q8j-958c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"}]}