A critical vulnerability, tracked as CVE-2025-59951, was discovered in the official Docker image for Termix, a web-based server management platform. This flaw allows unauthenticated access to sensitive SSH credentials stored within the application. The vulnerability arises from the way the Docker image is configured with an Nginx reverse proxy, which causes the backend to always interpret incoming requests as originating from localhost. Specifically, the backend uses the req.ip method to determine the client's IP address, but due to the proxy configuration, it always receives the proxy's IP, resulting in the isLocalhost check returning true for all requests. As a result, the /ssh/db/host/internal endpoint, which stores SSH host information including addresses, usernames, and passwords, can be accessed without any authentication. This exposes all stored SSH credentials to anyone who can reach the endpoint, representing a severe security risk. The vulnerability affects all users of the official Termix Docker image up to and including version 1.5.0, as well as those who build their own images using the official Dockerfile or utilize the reverse proxy functionality. The issue is remotely exploitable, meaning attackers do not need local access to exploit the flaw. The vulnerability was assigned a CVSS 4.0 score of 9.2, indicating its critical severity. The problem has been addressed in Termix version 1.6.0, which corrects the proxy configuration to ensure proper client IP detection and authentication enforcement. Users are strongly advised to upgrade to version 1.6.0 or later to mitigate the risk. The vulnerability was publicly disclosed on October 1, 2025, and security advisories were issued to inform affected users. The exposure of SSH credentials could allow attackers to gain unauthorized access to managed servers, potentially leading to further compromise. Organizations using Termix in production environments are particularly at risk if they have not yet applied the update. The flaw highlights the importance of secure reverse proxy configurations and proper authentication checks in web-based management tools. Security researchers recommend auditing similar configurations in other applications to prevent analogous vulnerabilities. The incident underscores the need for timely patching and vigilant monitoring of security advisories for critical infrastructure components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Termix addressed CVE-2025-59951 in version 1.6.0 and advised users to upgrade and review access controls for the exposed endpoint. This remediation closed the authentication bypass affecting earlier versions.
A critical authentication bypass vulnerability in the official Termix Docker image allowed unauthenticated access to the /ssh/db/host/internal endpoint because the backend trusted the reverse proxy IP as localhost. The flaw could expose stored SSH host data including addresses, usernames, and passwords in affected deployments using the official image, official Dockerfile, or reverse proxy functionality.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.