{"id":"CVE-2026-79764","title":"Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities","summary":"Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-918"],"vendor":"Termix-SSH","product":"Termix","affected":["Termix >= 2.5.0, < 2.5.1"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T19:39:45.600","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79764","references":[{"url":"https://github.com/Termix-SSH/Termix/commit/4b2a60a854281d0e12e7c9bcde71854a81999ea0","label":"security-advisories@github.com"},{"url":"https://github.com/Termix-SSH/Termix/commit/ddbdd5c437c2296607dfaa4265d6f63fbc1ca92e","label":"security-advisories@github.com"},{"url":"https://github.com/Termix-SSH/Termix/pull/1067","label":"security-advisories@github.com"},{"url":"https://github.com/Termix-SSH/Termix/releases/tag/release-2.5.1-tag","label":"security-advisories@github.com"},{"url":"https://github.com/Termix-SSH/Termix/security/advisories/GHSA-mwr3-35ph-pjqg","label":"security-advisories@github.com"},{"url":"https://github.com/Termix-SSH/Termix/security/advisories/GHSA-mwr3-35ph-pjqg","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-24T17:19:08.241522Z"},"ingestedAt":"2026-09-24T16:47:15.895Z","slug":"CVE-2026-79764","body":"## Overview\n\nTermix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing requests to loopback, RFC1918, link-local, and cloud metadata destinations. The endpoint returns the complete fetched JSON response, so a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials. This issue is fixed in version 2.5.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":210299,"id":"CVE-2026-79764","ts":1790272146556,"field":"exploit_available","old":"false","new":"true"}]}