CVE-2026-45748: Termix
Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3.2 builds an SSH tunnel command by interpolating user-controlled host record fields (`endpointIP`, `endpointUsername`, `password`) directly into a shell command without escaping, allowing persistent OS command injection on the source SSH host. Version 2.3.2 patches the issue.
Affected products
- Termix Termix: from 2.1.0, before 2.3.2 (fixed in 2.3.2)
Published 2026-06-05. Last modified 2026-06-17.