Tabby
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 8 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 26, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Tabby: Windows SFTP path traversal allows a malicious server to write files outside the selected download directory
Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)
Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution
Tabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zsh
Tabby: RCE via `tabby://run` URL Scheme
Tabby: Unsafe protocol handler execution via terminal linkifier allows arbitrary OS protocol invocation
Tabby has a TCC Bypass via Misconfigured Node Fuses
Tabby has a TCC Bypass via Unnecessary Permissive Entitlements in Tabby
Monitor Tabby in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.