PT-2026-97919 · Termix · Termix
CVE-2026-79761
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Termix versions 1.7.0 through 2.5.0
Description
Termix is a web-based server management platform providing SSH terminal, tunneling, and file editing. An authenticated user can execute arbitrary commands with the privileges of the selected remote account by deploying a crafted SSH credential. This occurs because the SSH key deployment flow derives a grep pattern from a user-controlled public-key token and interpolates it into double-quoted shell commands executed on the target host. Specifically, in
src/backend/database/routes/credential-deploy-routes.ts, the keyPattern variable in both grep -F verification paths allows command substitution or quote-breaking shell syntax.Recommendations
Update to version 2.5.1.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Termix