CVE-2026-46709: Tabby

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete CVE-2026-45038 fix for control characters still allows code execution when the victim presses Enter. This issue is fixed in version 1.0.234.

Affected products

  • Tabby Tabby: before 1.0.234 (fixed in 1.0.234)

Published 2026-07-15. Last modified 2026-07-30.