216.73.217.22

CVE-2026-45038

· Published 15/05/2026 17:16 · Modified 15/05/2026 19:17

Labels: CVE-2026-45038 2026-05-15CVE-2026-45038CWE-150[email protected]

Essential information

Published
15/05/2026 17:16
Modified
15/05/2026 19:17
Author
Creator
CVSS
8.4 HIGH (v3) 8.4 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerability is fixed in 1.0.233.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
tabby / tabby cpe:2.3:a:tabby:tabby:<1.0.233:*:*:*:*:*:*

References