CVE-2026-72903

8.1

Eugeny · tabby

Tabby terminal emulator is vulnerable to a path traversal flaw, allowing an attacker to potentially access or manipulate unauthorized files.

Executive summary

A path traversal vulnerability in the Eugeny Tabby terminal emulator allows unauthenticated attackers to potentially impact system integrity and availability.

Vulnerability

This vulnerability is a path traversal flaw (CWE-22) residing in the terminal emulator, which can be triggered by an unauthenticated attacker through user interaction.

Business impact

With a CVSS score of 8.1, this vulnerability represents a high risk to business operations. Exploitation could allow an attacker to bypass directory restrictions, leading to unauthorized file system access, which may result in system compromise or service disruption.

Remediation

Immediate Action: Update the Tabby terminal emulator to version 1.0.235 or later to resolve the underlying path traversal issue.

Proactive Monitoring: Monitor system logs for unusual file access patterns or unexpected path traversal attempts originating from the terminal application.

Compensating Controls: Ensure that the application is running with the principle of least privilege to limit the scope of impact if a traversal attack is successful.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high severity score, organizations should prioritize updating all instances of Tabby to version 1.0.235 immediately. Failure to patch leaves the system exposed to potential file system traversal attacks that could compromise the integrity of the host environment.