PT-2026-97923 · Termix · Termix
CVE-2026-79766
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Termix versions 2.4.1 through 2.5.0
Description
An authenticated administrator can execute arbitrary operating-system commands as the backend process. This occurs because the application fails to properly sanitize domain and email values stored via the 'PATCH /users/acme-ssl-settings' endpoint before they are interpolated into a certbot shell command triggered by the 'POST /users/acme-ssl-request' endpoint. Specifically, in
src/backend/database/routes/acme-ssl-routes.ts, the child process.execSync function invokes /bin/sh -c with these values wrapped only in double quotes, allowing shell metacharacters to be processed. This affects both HTTP webroot and DNS Cloudflare challenge modes, potentially exposing databases, process secrets, stored credentials, and network reachability.Recommendations
Update to version 2.5.1.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Termix