CVE-2026-79764: Termix-SSH Termix
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing requests to loopback, RFC1918, link-local, and cloud metadata destinations. The endpoint returns the complete fetched JSON response, so a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials. This issue is fixed in version 2.5.1.
Affected products
- Termix-SSH Termix: from 2.5.0, before 2.5.1 (fixed in 2.5.1)
Published 2026-09-24. Last modified 2026-09-24.