CVE-2026-79764
Termix: Authenticated SSRF via `/homepage/proxy` โ No Destination Allowlist
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing requests to loopback, RFC1918, link-local, and cloud metadata destinations. The endpoint returns the complete fetched JSON response, so a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials. This issue is fixed in version 2.5.1.
| CWE | CWE-918 |
| Vendor | termix-ssh |
| Product | termix |
| Published | Sep 24, 2026 |
| Last Updated | Sep 24, 2026 |
Get instant alerts for termix-ssh termix
Be the first to know when new high vulnerabilities affecting termix-ssh termix are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N