References https://nvd.nist.gov/vuln/detail/CVE-2023-31716 https://github.com/MateusTesser/CVE-2023-31716 https://github.com/frangoteam/FUXA https://cve.imfht.com/detail/CVE-2023-31716 https://www.miggo.io/vulnerability-database/cve/CVE-2023-31716 https://security.snyk.io/vuln/SNYK-JS-FRANGOTEAMFUXA-5915274 https://www.cve.org/CVERecord?id=CVE-2023-31716 https://advisories.gitlab.com/npm/@frangoteam/fuxa/CVE-2023-31716/ https://www.acunetix.com/vulnerabilities/sca/cve-2023-31716-vulnerability-in-npm-package-frangoteam-fuxa/
Related VulnerabilitiesPoCCVE-2026-25895: FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File WritePoCCVE-2026-47717: FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data DisclosureFUXA /api/project 信息泄露漏洞(CVE-2026-47717)FUXA /socket.io 服务器端请求伪造漏洞(CVE-2026-47719)FUXA /api/runscript 代码执行漏洞(CVE-2026-43947)FUXA /api/download 文件读取漏洞(CVE-2023-31718)FUXA /api/project 权限绕过漏洞(CVE-2025-69971)PoCCVE-2025-69971: FUXA <= 1.2.7 - Hardcoded JWT Secret Authentication BypassPoCCVE-2023-33831: FUXA - Unauthenticated Remote Code ExecutionFUXA /runscript 命令执行漏洞(CVE-2023-33831)FUXA CVE-2023-33831 任意命令执行漏洞