Path Traversal Vulnerability in Tabby Terminal Emulator
CVE-2026-72903

8.1HIGH

Key Information:

Vendor

Eugeny

Status
Vendor
CVE Published:
10 August 2026

What is CVE-2026-72903?

The Tabby terminal emulator is affected by a path traversal vulnerability that allows a malicious SFTP server to manipulate filename handling. When processing directory listings and file downloads, the application improperly treats backslashes as valid characters instead of escaping them. This oversight enables attackers to craft filenames that exploit path traversal mechanisms, potentially allowing unintended access to files outside the intended directories. The vulnerability is mitigated in version 1.0.235.

Affected Version(s)

tabby < 1.0.235

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.