CVE-2026-45038

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerability is fixed in 1.0.233.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:tabby:tabby:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-15 17:16

Updated : 2026-06-17 10:51


NVD link : CVE-2026-45038

Mitre link : CVE-2026-45038

CVE.ORG link : CVE-2026-45038


JSON object : View

Products Affected

tabby

  • tabby
CWE
CWE-150

Improper Neutralization of Escape, Meta, or Control Sequences