CVE-2026-22804

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 to 1.9.0, Stored Cross-Site Scripting (XSS) vulnerability exists in the Termix File Manager component. The application fails to sanitize SVG file content before rendering it. This allows an attacker who has compromised a managed SSH server to plant a malicious file, which, when previewed by the Termix user, executes arbitrary JavaScript in the context of the application. The vulnerability is located in src/ui/desktop/apps/file-manager/components/FileViewer.tsx. This vulnerability is fixed in 1.10.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:termix:termix:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:20

Type Values Removed Values Added
Summary
  • (es) Termix es una plataforma de gestión de servidores basada en web con capacidades de terminal SSH, tunelización y edición de archivos. Desde la versión 1.7.0 hasta la 1.9.0, existe una vulnerabilidad de cross-site scripting (XSS) almacenado en el componente Termix File Manager. La aplicación no logra sanear el contenido de archivos SVG antes de renderizarlo. Esto permite a un atacante que ha comprometido un servidor SSH gestionado plantar un archivo malicioso, el cual, al ser previsualizado por el usuario de Termix, ejecuta JavaScript arbitrario en el contexto de la aplicación. La vulnerabilidad se encuentra en src/ui/desktop/apps/file-manager/components/FileViewer.tsx. Esta vulnerabilidad se corrigió en la versión 1.10.0.

16 Jan 2026, 18:37

Type Values Removed Values Added
References () https://github.com/Termix-SSH/Termix/security/advisories/GHSA-m3cv-5hgp-hv35 - () https://github.com/Termix-SSH/Termix/security/advisories/GHSA-m3cv-5hgp-hv35 - Exploit, Third Party Advisory
CPE cpe:2.3:a:termix:termix:*:*:*:*:*:*:*:*
First Time Termix termix
Termix

13 Jan 2026, 19:16

Type Values Removed Values Added
References () https://github.com/Termix-SSH/Termix/security/advisories/GHSA-m3cv-5hgp-hv35 - () https://github.com/Termix-SSH/Termix/security/advisories/GHSA-m3cv-5hgp-hv35 -

12 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-12 23:15

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22804

Mitre link : CVE-2026-22804

CVE.ORG link : CVE-2026-22804


JSON object : View

Products Affected

termix

  • termix
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-269

Improper Privilege Management