CVE-2025-22136: Tabby has a TCC Bypass via Misconfigured Node Fuses
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection vectors even though the application is signed with hardened runtime and lacks dangerous entitlements such as com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables. This vulnerability is fixed in 1.0.217.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22136?
CVE-2025-22136 is considered a high severity vulnerability due to the potential for code injection.
How do I fix CVE-2025-22136?
To remediate CVE-2025-22136, upgrade to Tabby version 1.0.217 or later.
What software is affected by CVE-2025-22136?
CVE-2025-22136 affects Tabby versions prior to 1.0.217.
What type of vulnerability is CVE-2025-22136?
CVE-2025-22136 is a code injection vulnerability related to high-risk Electron Fuses.
Can CVE-2025-22136 lead to remote code execution?
Yes, CVE-2025-22136 can potentially lead to remote code execution due to the code injection vectors it creates.