Web-Based Server Management Platform Vulnerability in Termix by LukeGus
CVE-2025-59951
What is CVE-2025-59951?
The web-based server management platform, Termix, is susceptible to an authentication bypass vulnerability due to improper handling of IP addresses when configured with an Nginx reverse proxy. In versions 1.5.0 and below, this misconfiguration leads to the backend reporting the proxy's IP instead of the client's. As a result, access to the sensitive /ssh/db/host/internal endpoint can be gained without proper authentication, potentially exposing critical SSH host information, including usernames and passwords. Users leveraging the official Termix Docker image, custom images built from the Dockerfile, or using reverse proxy setups are vulnerable. The issue is addressed in version 1.6.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Termix < 1.6.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
