Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53546— Termix: Missing authorization in SSH host credential resolution exposes stored credentials

Quick assessment

Affected
Termix-SSH Termix
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

termix是termix个人开发者的一个终端模拟器。 Termix 2.3.2之前版本存在授权问题漏洞,该漏洞源于终端WebSocket接受用户控制的hostConfig.id,解析主机时未要求所有权或显式访问,并执行所有者凭据回退,将凭据与攻击者控制的IP、端口和用户名组合,可能导致认证的低权限用户向攻击者控制的SSH服务器认证并泄露其他用户存储的SSH密码或私钥材料。

CVSS 9.6 · Critical EPSS 0.36% · P30

Possible ATT&CK Techniques 1 AI

T1552.004 · Private Keys

Affected Version Matrix 1

VendorProduct Version RangeStatus
Termix-SSH Termix < 2.3.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53546

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Termix: Missing authorization in SSH host credential resolution exposes stored credentials
Source: CVE Program / CVE List V5
Vulnerability Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves that host without requiring ownership or explicit access. When no credential is shared with the requester, resolveHostById performs an owner credential fallback, and src/backend/ssh/terminal.ts combines that credential with attacker-controlled ip, port, and username values. An authenticated low-privileged user can therefore make Termix authenticate to an attacker-controlled SSH server and disclose another user's stored SSH password or private-key material while the victim user's data key is unlocked. This issue is fixed in version 2.3.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5
Vulnerability Title
Termix 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
termix是termix个人开发者的一个终端模拟器。 Termix 2.3.2之前版本存在授权问题漏洞,该漏洞源于终端WebSocket接受用户控制的hostConfig.id,解析主机时未要求所有权或显式访问,并执行所有者凭据回退,将凭据与攻击者控制的IP、端口和用户名组合,可能导致认证的低权限用户向攻击者控制的SSH服务器认证并泄露其他用户存储的SSH密码或私钥材料。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Termix-SSH Termix < 2.3.2 -

II. Public POCs for CVE-2026-53546

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 8911 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-53546

登录查看更多情报信息。

Patches & Fixes for CVE-2026-53546 (1)

Vendor Advisories for CVE-2026-53546 (1)

Same Patch Batch · Termix-SSH · 2026-08-19 · 6 CVEs total

CVE-2026-53545 9.8 CRITICAL Termix: Remote Code Execution via Tunnel Disconnect pkill Command Injection
CVE-2026-53548 9.6 CRITICAL Termix: IDOR — Authenticated user can fetch SSH passwords for hosts owned by other users
CVE-2026-53547 8.8 HIGH Termix: Account Takeover via Global Settings Disclosure
CVE-2026-53542 8.8 HIGH Termix: Tar option injection in file-manager archive creation allows command execution on
CVE-2026-53549 7.7 HIGH Termix: Server-Side Request Forgery via Proxy Connectivity Test

IV. Related Vulnerabilities

V. Comments for CVE-2026-53546

No comments yet


Leave a comment