AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-67443 is a critical vulnerability in FUXA 1.3.2 and earlier versions. The vulnerability exists in the allowDashboard authorization gate in server/integrations/node-red/index.js, where the decoded identity is not inspected when nodeRedEnabled is true, secureEnabled is true, and nodeRedAuthMode is secure. This oversight allows remo [truncated]
FUXA, a web-based Process Visualization software, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 1.3.2. This vulnerability allows a remote unauthenticated attacker to make server/runtime/devices/httprequest/index.js call axios.get against arbitrary HTTP or HTTPS destinations, connect to reachable OPC UA or ODBC services, and receive results through the corresponding Socket.IO [truncated]
CVE-2026-43946 is a high-severity vulnerability in FUXA, a web-based Process Visualization software. Version 1.3.0 has an authorization bypass issue in the /api/getTagValue endpoint, allowing unauthenticated access to tag values when a referenced script does not exist. The issue was patched in version 1.3.1. This vulnerability has significant implications for organizations using FUXA, as it could allow at [truncated]