Termix是Karmaa个人开发者的一个服务器管理平台。 Termix 2.1.0之前版本存在操作系统命令注入漏洞,该漏洞源于Docker容器管理端点未对containerId参数进行清理或验证,可能导致经过身份验证的攻击者注入任意OS命令并实现远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Termix-SSH | Termix | < 2.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Termix-SSH | Termix | < 2.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42452 | 8.1 HIGH | Termix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTP |
| CVE-2026-42453 | Termix: Command injection in extractArchive/compressFiles via double-quote escaping bypass |
No comments yet