CVE-2025-69983 is a critical Remote Code Execution (RCE) vulnerability affecting FUXA v1.2.7, specifically within its project import functionality. The flaw stems from insufficient sanitization and sandboxing of user-supplied scripts in imported project files. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows unauthenticated attackers to execute arbitrary system commands, leading to full system compromise. While currently not listed in KEV or Hot Lists, and with no public exploit intelligence or community discussion, its high severity warrants immediate attention for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.7CPE matchmatch criteria | cpe:2.3:a:frangoteam:fuxa:1.2.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.