CVE-2026-45038: Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape control characters from file paths when dragging and dropping a file into it, code execution can be achieved. This vulnerability is fixed in 1.0.233.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45038?
CVE-2026-45038 is considered to be a high severity vulnerability as it allows code execution through file drag and drop.
How do I fix CVE-2026-45038?
To fix CVE-2026-45038, update Tabby to version 1.0.233 or later where the vulnerability has been addressed.
What versions are affected by CVE-2026-45038?
CVE-2026-45038 affects all versions of Tabby prior to 1.0.233.
What can an attacker do with CVE-2026-45038?
An attacker can execute arbitrary code on the system by leveraging the drag and drop file functionality in Tabby.
Is there a workaround for CVE-2026-45038 before applying a fix?
A recommended workaround for CVE-2026-45038 is to avoid using the drag and drop feature in Tabby until the software is updated.