Please report any vulnerabilities to GitHub Security.
Security: Termix-SSH/Termix
Security
SECURITY.md
-
Remote Code Execution via SSH Tunnel Forward Command InjectionGHSA-xmjh-8cc2-qm49 published
May 31, 2026 by ZacharyZcRCritical -
File-Manager Session Hijack via Missing Ownership Check (IDOR)GHSA-5fqh-77cr-jj5x published
May 31, 2026 by ZacharyZcRHigh -
TOTP two-factor authentication can be disabled or bypassed using only the account passwordGHSA-wqfw-rqj7-fv9m published
May 31, 2026 by ZacharyZcRHigh -
Authenticated users can access bcrypt password hashes of all users via /users/listGHSA-ccm8-q457-6vjj published
May 31, 2026 by ZacharyZcRHigh -
OS Command Injection in File Manager resolvePath endpointGHSA-37f4-wq95-pg33 published
May 31, 2026 by ZacharyZcRCritical -
Arbitrary Command Execution in File ManagerGHSA-v26q-rpv5-9m72 published
May 31, 2026 by ZacharyZcRCritical -
Arbitrary Command Execution via Session HijackingGHSA-cx2r-843c-vww8 published
May 31, 2026 by ZacharyZcRCritical -
OS Command Injection in Docker Container Management EndpointsGHSA-c2g2-hqgq-6w9v published
Apr 22, 2026 by LukeGusCritical -
Pending-TOTP temporary token can regenerate backup codes and neutralize TOTPGHSA-vx59-rf9w-9jv8 published
Apr 22, 2026 by LukeGusHigh -
Improper certificate validation in Electron desktop client enables MITM credential/token theftGHSA-r9gw-3w87-mhh7 published
May 12, 2026 by LukeGusHigh
Learn more about advisories related to Termix-SSH/Termix in the GitHub Advisory Database