CVE-2026-45038: Tabby

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerability is fixed in 1.0.233.

Affected products

  • Tabby Tabby: before 1.0.233 (fixed in 1.0.233)

Published 2026-05-15. Last modified 2026-06-17.