PT-2026-97922 · Termix · Termix

CVE-2026-79764

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Termix versions 2.5.0 through 2.5.0
Description The '/homepage/proxy' endpoint accepts a url query parameter from an authenticated user and passes it to http.get or https.get without destination restrictions. In the file src/backend/database/routes/homepage-proxy-routes.ts, the new URL function performs only syntactic validation. This allows requests to loopback, RFC1918 (private IP addresses), link-local, and cloud metadata destinations. Because the endpoint returns the complete fetched JSON response, a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials.
Recommendations Update to version 2.5.1. Avoid using the url parameter in the '/homepage/proxy' endpoint until the update is applied.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79764
GHSA-MWR3-35PH-PJQG

Affected Products

Termix