Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Termix
Termix termix |
|
| Vendors & Products |
Termix
Termix termix |
Thu, 24 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, the Termix SSH key deployment flow derives a grep pattern from a user-controlled public-key token and interpolates it into double-quoted shell commands executed on the selected target host. In src/backend/database/routes/credential-deploy-routes.ts, both grep -F verification paths accept command substitution or quote-breaking shell syntax in keyPattern. An authenticated user who can deploy a crafted SSH credential can therefore execute commands with the selected remote account's privileges. The separate ACME command-injection report is outside this CVE's scope. This issue is fixed in version 2.5.1. | |
| Title | Termix: Command injection in SSH key deployment verification | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T15:33:48.142Z
Reserved: 2026-08-25T14:08:18.110Z
Link: CVE-2026-79761
Updated: 2026-10-05T14:47:11.557Z
Status : Deferred
Published: 2026-09-24T16:17:11.743
Modified: 2026-10-05T16:17:16.427
Link: CVE-2026-79761
No data.
OpenCVE Enrichment
Updated: 2026-09-25T14:17:16Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')