Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/termix-ssh/Termix

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-53545 is a critical OS command injection vulnerability in Termix, a web-based server management platform. The flaw exists in versions prior to 2.3.2 in the DELETE /ssh/tunnel/disconnect/:tunnelName endpoint, where user-controlled input is improperly sanitized and interpolated into shell commands. An authenticated user able to edit tunnel host fields can inject arbitrary shell commands that execute with the privileges of the connected SSH account when the tunnel disconnects. This allows remote command execution on the source SSH host. The issue is fixed in Termix version 2.3.2.

Join the discussion

CVE-2026-53546 is a critical authorization bypass vulnerability in Termix, a web-based server management platform. Versions prior to 2.3.2 allow an authenticated low-privileged user to exploit a flaw in the terminal WebSocket host resolution process. The vulnerability arises because the system accepts a user-controlled hostConfig.id and resolves it without verifying ownership or explicit access. This can lead to Termix authenticating to an attacker-controlled SSH server and disclosing another user's stored SSH credentials while their data key is unlocked. The issue is fixed in Termix version 2.3.2.

Join the discussion

CVE-2026-53542 is an OS command injection vulnerability in Termix-SSH's Termix platform prior to version 2.3.2. The flaw exists in the archive creation endpoint where file basenames are passed to the tar command without proper sanitization or an end-of-options marker. This allows an attacker with SSH file-manager access to craft filenames that are interpreted as tar options, leading to arbitrary command execution with the privileges of the SSH user. The vulnerability is fixed in version 2.3.2.

Join the discussion

CVE-2026-53548 is a critical improper authorization vulnerability in Termix-SSH's Termix platform prior to version 2.6.1. It allows any authenticated user with a valid JWT to enumerate host IDs and retrieve plaintext SSH or sudo passwords of other users by exploiting insufficient host ownership checks on a specific API endpoint. This can lead to unauthorized access and control of managed systems outside the Termix instance. The issue is fixed in version 2.6.1.

Join the discussion

CVE-2026-53547 is a high-severity vulnerability in Termix, a web-based server management platform. Versions prior to 2.3.2 have a missing authorization check in the POST /database/export endpoint, which exports global settings including sensitive password-reset artifacts. This flaw allows a low-privileged authenticated user to obtain reset codes of other local accounts, enabling account takeover and potential administrative compromise. The issue is fixed in Termix version 2.3.2.

Join the discussion

CVE-2026-53549 is a Server-Side Request Forgery (SSRF) vulnerability in Termix, a web-based server management platform. Versions prior to 2.3.2 have an issue in the POST /host/db/proxy/test endpoint where certain request fields are not validated for destination addresses. This allows an authenticated user to make raw TCP and SOCKS connections to arbitrary hosts and ports accessible from the Termix server, including localhost and private network resources. Exploitation can disclose host reachability, timing information, and potentially expose cloud credentials via metadata services. The vulnerability is fixed in version 2.3.2.

Join the discussion

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in the Termix File Manager component unsafely processes the path parameter and embeds it into a shell command executed over the active SSH session. Because the user-controlled value is placed inside double quotes and only double quotes are escaped, shell command substitution syntax such as $(...) is still interpreted by the remote shell. Version 2.3.2 fixes the issue.

Join the discussion

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` endpoints in Termix prior to version 2.3.2 accept the account password as a sole authentication factor for MFA-critical operations. An attacker who obtains a user's password (phishing, credential stuffing, the passwordHash leak in GHSA-xxxx) can disable TOTP entirely or regenerate backup codes, without ever possessing the TOTP device or knowing a valid TOTP code. This renders two-factor authentication ineffective. Version 2.3.2 patches the issue.

Join the discussion

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3.2 builds an SSH tunnel command by interpolating user-controlled host record fields (`endpointIP`, `endpointUsername`, `password`) directly into a shell command without escaping, allowing persistent OS command injection on the source SSH host. Version 2.3.2 patches the issue.

Join the discussion

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manager functionality in Termix contains a critical Broken Access Control vulnerability due to improper validation of the sessionId parameter. The backend trusts a client-controlled identifier without verifying that it belongs to the authenticated user. This allows an attacker to manipulate the value and access active File Manager sessions belonging to other users. Since these sessions are tied to SSH connections to remote VPS instances, exploitation allows unauthorized interaction with another user's remote filesystem. Because the File Manager exposes functionality such as file reading, writing, uploading, and execution, this vulnerability enables direct command execution on another user's VPS (RCE). Version 2.3.2 patches the issue.

Join the discussion

Showing 1 to 10 of 16 results

Filters:Package: pkg:github/termix-ssh/Termix
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses