Executive brief
Termix is a web-based platform used by administrators to manage servers through SSH terminals and file management tools. A security flaw allows an authenticated user to hijack the active sessions of other users if they can identify the session ID. This could allow an attacker to read, modify, or delete sensitive files and execute commands on servers they are not authorized to access, potentially leading to a full system compromise.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in 16 file-manager endpoints of Termix (including readFile, writeFile, and executeFile). While a verification helper exists, it is not consistently applied across all endpoints that access the 'sshSessions' object via a user-provided 'sessionId'. An authenticated attacker who knows or guesses a victim's active UUID-based sessionId can bypass authorization checks to interact with the victim's connected SSH host. This allows for unauthorized file system access and arbitrary command execution on the remote host. The issue is addressed in version 2.3.2 by enforcing ownership checks and moving session ID generation to the server side.
Affected products
- Termix-SSH Termix < 2.3.2
Timeline
- 2026-05-31: advisory: GitHub Security Advisory published
- 2026-06-04: patched: Version 2.3.2 released
- 2026-06-05: disclosed: CVE published to NVD