Please report any vulnerabilities to GitHub Security.
Security: Termix-SSH/Termix
Security
SECURITY.md
-
Authenticated blind SSRF through notification channel test endpointsGHSA-6hx3-9mgq-h9fj published
Jul 27, 2026 by ZacharyZcRModerate -
Cross-user Docker session control and unbound RBAC share deletionGHSA-pcmm-36f6-36q6 published
Jul 27, 2026 by ZacharyZcRHigh -
Command injection in SSH key deployment verificationGHSA-p2g3-2xq3-23gx published
Jul 27, 2026 by ZacharyZcRModerate -
OIDC login allows session-token theft and trusts unsigned ID-token claims on verification errorsGHSA-fmwq-x6v6-3q8w published
Jul 27, 2026 by ZacharyZcRHigh -
Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — full offline decryption from a database copyGHSA-685g-ccvv-6p8m published
Jul 27, 2026 by ZacharyZcRModerate -
Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)GHSA-x9h9-f7jc-8jwj published
Jul 27, 2026 by ZacharyZcRModerate -
Authenticated SSRF via `/homepage/proxy` — No Destination AllowlistGHSA-mwr3-35ph-pjqg published
Jul 27, 2026 by ZacharyZcRHigh -
The S2S tunnel endpoint-host resolver in tunnel.ts matches tunnelConfig.endpointHost against every user's hosts by display name or username@ip, then decrypts that host's password/key using its real owner's key, letting any authenticated user steal another user's working SSH credentials by guessing a host nameGHSA-vx7c-4gxw-vr2h published
Jul 27, 2026 by ZacharyZcRCritical -
OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/emailGHSA-pr55-25gf-5f9v published
Jul 27, 2026 by ZacharyZcRCritical -
Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host EndpointGHSA-w4cf-69fj-g96f published
Jul 27, 2026 by ZacharyZcRModerate
Learn more about advisories related to Termix-SSH/Termix in the GitHub Advisory Database