OS Command Injection in Termix Web-Based Server Management Platform
CVE-2026-45744
9.9CRITICAL
What is CVE-2026-45744?
Termix, a web-based server management platform, is susceptible to OS command injection vulnerabilities due to improper shell command construction at the /ssh/file_manager/ssh/resolvePath endpoint. This flaw allows authenticated users with an active File Manager SSH session to execute arbitrary commands on a connected remote host. The issue arises from the use of double-quote escaping, which fails to mitigate command substitution techniques using $(...) and backticks. Version 2.3.2 addresses this vulnerability.
Affected Version(s)
Termix < 2.3.2
