Path Traversal Vulnerability in Tabby Terminal Emulator
CVE-2026-72903
8.1HIGH
What is CVE-2026-72903?
The Tabby terminal emulator is affected by a path traversal vulnerability that allows a malicious SFTP server to manipulate filename handling. When processing directory listings and file downloads, the application improperly treats backslashes as valid characters instead of escaping them. This oversight enables attackers to craft filenames that exploit path traversal mechanisms, potentially allowing unintended access to files outside the intended directories. The vulnerability is mitigated in version 1.0.235.
Affected Version(s)
tabby < 1.0.235
