Home

Description

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 to 1.9.0, Stored Cross-Site Scripting (XSS) vulnerability exists in the Termix File Manager component. The application fails to sanitize SVG file content before rendering it. This allows an attacker who has compromised a managed SSH server to plant a malicious file, which, when previewed by the Termix user, executes arbitrary JavaScript in the context of the application. The vulnerability is located in src/ui/desktop/apps/file-manager/components/FileViewer.tsx. This vulnerability is fixed in 1.10.0.

PUBLISHED Reserved 2026-01-09 | Published 2026-01-12 | Updated 2026-01-13 | Assigner GitHub_M




HIGH: 8.0CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Problem types

CWE-269: Improper Privilege Management

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

>= 1.7.0, < 1.10.0
affected

References

github.com/...Termix/security/advisories/GHSA-m3cv-5hgp-hv35 exploit

github.com/...Termix/security/advisories/GHSA-m3cv-5hgp-hv35

cve.org (CVE-2026-22804)

nvd.nist.gov (CVE-2026-22804)

Download JSON