highCVSS 8.1Vulnerability
GHSA-c8m8-3jcr-6rj5
FUXA used a static fallback JWT signing secret (`frangoteam751`) when no `secretCode` was configured. If authentication was enabled without explicitly setting a custom secret, an attacker who knew the default value could forge valid JWT tokens and bypass authentication. This issue has been addressed in version 1.3.0 by removing the static fallback and generating a secure random secret when no `secretCode` is provided.
Properties
- ghsa_id
- GHSA-c8m8-3jcr-6rj5
- severity
- high
- summary
- FUXA has a hardcoded fallback JWT signing secret
- cvss_score
- 8.1
- cve_id
- GHSA-c8m8-3jcr-6rj5
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-03-07T02:31:18Z
- source_url
- https://github.com/advisories/GHSA-c8m8-3jcr-6rj5
- ghsa_updated
- 2026-03-07T03:16:21Z
Related Entities (3)
AFFECTS (1)
→[Software]npm/@frangoteam/fuxa
HAS_WEAKNESS (1)
→[Weakness]Use of Hard-coded Cryptographic Key
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph