Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-79764— Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist

Quick assessment

Affected
Termix-SSH Termix
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Termix 是一个基于 Web 的服务器管理平台,提供 SSH 终端、隧道转发和文件编辑等功能。在版本 2.5.0 至 2.5.1 中, 端点接受已认证用户的 查询参数,并将其直接传递给 或 ,且未对目标地址进行任何限制。在 文件中, 仅执行语法层面的验证,允许请求访问回环地址(loopback)、RFC1918 私有地址、链路本地地址以及云元数据服务地址。该端点会返回完整获取的 JSON 响应,因此,低权限用户或自行注册的用户可以借此泄露内部服务数据和云凭证。此问题已在版本 2.5.1 中修复。

CVSS 7.7 · High EPSS 0.42% · P34
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79764

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist
Source: CVE Program / CVE List V5
Vulnerability Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing requests to loopback, RFC1918, link-local, and cloud metadata destinations. The endpoint returns the complete fetched JSON response, so a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials. This issue is fixed in version 2.5.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Termix-SSH Termix >= 2.5.0, < 2.5.1 -

II. Public POCs for CVE-2026-79764

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79764

请登录查看更多情报信息。

Other References for CVE-2026-79764 (5)

Same Patch Batch · Termix-SSH · 2026-09-24 · 8 CVEs total

CVE-2026-79766 9.1 CRITICAL Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c
CVE-2026-79761 6.6 MEDIUM Termix: Command injection in SSH key deployment verification
CVE-2026-79760 6.4 MEDIUM Termix: Authenticated blind SSRF through notification channel test endpoints
CVE-2026-79762 5.5 MEDIUM Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — f
CVE-2026-79758 5.4 MEDIUM Termix: Authenticated users can read other users' host status and clear global SSH connect
CVE-2026-79763 5.3 MEDIUM Termix: MFA-critical operations accept the account password as a sole factor (regression o
CVE-2026-79759 4.3 MEDIUM Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En

IV. Related Vulnerabilities

V. Comments for CVE-2026-79764

No comments yet


Leave a comment