CVE-2026-72903
8.1Eugeny · tabby
Tabby terminal emulator is vulnerable to a path traversal flaw, allowing an attacker to potentially access or manipulate unauthorized files.
Executive summary
A path traversal vulnerability in the Eugeny Tabby terminal emulator allows unauthenticated attackers to potentially impact system integrity and availability.
Vulnerability
This vulnerability is a path traversal flaw (CWE-22) residing in the terminal emulator, which can be triggered by an unauthenticated attacker through user interaction.
Business impact
With a CVSS score of 8.1, this vulnerability represents a high risk to business operations. Exploitation could allow an attacker to bypass directory restrictions, leading to unauthorized file system access, which may result in system compromise or service disruption.
Remediation
Immediate Action: Update the Tabby terminal emulator to version 1.0.235 or later to resolve the underlying path traversal issue.
Proactive Monitoring: Monitor system logs for unusual file access patterns or unexpected path traversal attempts originating from the terminal application.
Compensating Controls: Ensure that the application is running with the principle of least privilege to limit the scope of impact if a traversal attack is successful.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high severity score, organizations should prioritize updating all instances of Tabby to version 1.0.235 immediately. Failure to patch leaves the system exposed to potential file system traversal attacks that could compromise the integrity of the host environment.