CVE-2026-46709: Tabby
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete CVE-2026-45038 fix for control characters still allows code execution when the victim presses Enter. This issue is fixed in version 1.0.234.
Affected products
- Tabby Tabby: before 1.0.234 (fixed in 1.0.234)
Published 2026-07-15. Last modified 2026-07-30.