---
id: CVE-2026-65985
title: FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software
summary: >-
  FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In
  1.3.2 and earlier, the device-webapi-request Socket.IO handler in
  server/runtime/index.js permits an authenticated non-admin runtime user to
  control property.ad…
severity: none
cwe:
  - CWE-918
published: '2026-08-18'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:13:25.910'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-65985'
references:
  - url: >-
      https://github.com/frangoteam/FUXA/commit/4fa47d0a2a856ed34f427f472fb4450f86e7749b
    label: security-advisories@github.com
  - url: 'https://github.com/frangoteam/FUXA/pull/2379'
    label: security-advisories@github.com
  - url: 'https://github.com/frangoteam/FUXA/releases/tag/v1.3.3'
    label: security-advisories@github.com
  - url: 'https://github.com/frangoteam/FUXA/security/advisories/GHSA-wrg6-49wh-46pw'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00341
epssPercentile: 0.2768
ingestedAt: '2026-09-09T21:22:45.537Z'
---

## Overview

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server/runtime/index.js permits an authenticated non-admin runtime user to control property.address, causing the FUXA server to issue an outbound HTTP or HTTPS request and return the response body to the requesting socket. The attacker can use the server as a read SSRF oracle against reachable internal services or cloud metadata endpoints, with impact depending on the FUXA host's deployment network. This issue is fixed in version 1.3.3.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
