CVE-2026-45037

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without validating the protocol scheme. This allows a malicious SSH or Telnet server to send crafted terminal output containing dangerous protocol URIs which Tabby renders as clickable links, triggering arbitrary OS protocol handlers on the victim's machine. This vulnerability is fixed in 1.0.232.
References
Link Resource
https://github.com/Eugeny/tabby/security/advisories/GHSA-cmpc-v2x9-j9x9 Mitigation Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:tabby:tabby:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-15 17:16

Updated : 2026-06-17 10:51


NVD link : CVE-2026-45037

Mitre link : CVE-2026-45037

CVE.ORG link : CVE-2026-45037


JSON object : View

Products Affected

tabby

  • tabby
CWE
CWE-184

Incomplete List of Disallowed Inputs

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')