8
CVE-2026-45745
- EPSS 0.17%
- Veröffentlicht 05.06.2026 17:53:54
- Zuletzt bearbeitet 08.06.2026 15:02:28
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Termix has improper certificate validation in Electron desktop client that enables MITM credential/token theft
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation, allowing a machine-in-the-middle attacker to intercept and modify HTTPS traffic to the configured Termix server. This can lead to credential theft and JWT/session theft during login and normal use. As of time of publication, no known patched versions are available.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8 | 1.6 | 5.8 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
https://github.com/Termix-SSH/Termix/security/advisories/GHSA-r9gw-3w87-mhh7