PT-2026-97923 · Termix · Termix

CVE-2026-79766

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Termix versions 2.4.1 through 2.5.0
Description An authenticated administrator can execute arbitrary operating-system commands as the backend process. This occurs because the application fails to properly sanitize domain and email values stored via the 'PATCH /users/acme-ssl-settings' endpoint before they are interpolated into a certbot shell command triggered by the 'POST /users/acme-ssl-request' endpoint. Specifically, in src/backend/database/routes/acme-ssl-routes.ts, the child process.execSync function invokes /bin/sh -c with these values wrapped only in double quotes, allowing shell metacharacters to be processed. This affects both HTTP webroot and DNS Cloudflare challenge modes, potentially exposing databases, process secrets, stored credentials, and network reachability.
Recommendations Update to version 2.5.1.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79766
GHSA-PR55-25GF-5F9V

Affected Products

Termix