CVE-2026-79764: Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist

Published Sep 24, 2026
·
Updated

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing requests to loopback, RFC1918, link-local, and cloud metadata destinations. The endpoint returns the complete fetched JSON response, so a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials. This issue is fixed in version 2.5.1.

Affected Software

1 affected component
Termix Termix>=2.5.0<2.5.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Termix to a version that resolves this vulnerability.

    Fixed in 2.5.1

Event History

Sep 24, 2026
CVE Published
via MITRE·04:02 PM
Data Sourced
via MITRE·04:02 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Termix versions from 2.5.0 through versions before 2.5.1 are affected. The vulnerable endpoint can reach loopback, RFC1918, link-local, and cloud metadata destinations from the Termix server.

2

What access does an attacker need?

An attacker needs an authenticated Termix account and can exploit the issue with low-privilege or self-registered access. No user interaction is required.

3

What can an attacker obtain through the proxy endpoint?

The endpoint returns the complete fetched JSON response. This can expose data from internal services and cloud credentials available through metadata endpoints.

4

How can I determine whether a system is affected?

Check the deployed Termix version and whether users can access the /homepage/proxy endpoint while running a version before 2.5.1. The vulnerable behavior accepts a url query parameter without destination restrictions.

5

What is the available remediation?

Upgrade Termix to version 2.5.1, which fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203