PT-2026-78695 · Termix · Termix

CVE-2026-53549

·

Published

2026-08-19

·

Updated

2026-08-25

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Termix versions prior to 2.3.2
Description An authenticated user can probe localhost, private networks, link-local metadata services, and other infrastructure reachable from the server. This occurs because the 'POST /host/db/proxy/test' endpoint accepts the singleProxy, proxyChain, and testTarget request fields without validating their destination addresses. The testProxyConnectivity() path utilizes raw TCP and SOCKS connections to attacker-selected hosts and ports. Consequently, structured connection errors may disclose host reachability and timing information, while successful metadata access can expose cloud credentials.
Recommendations Update to version 2.3.2.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53549
GHSA-X9PR-795G-RM5F

Affected Products

Termix