PT-2026-41320 · Tabby · Tabby

CVE-2026-45035

·

Published

2026-05-15

·

Updated

2026-05-19

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Tabby versions prior to 1.0.233
Description Tabby registers itself as the handler for the tabby:// URL scheme across all platforms. The handler supports a run command that executes operating system commands without user confirmation, sanitization, or sandboxing. An attacker can deliver a malicious link using the tabby://run?command=... format via websites, emails, or chat messages. When a user clicks the link, the application spawns the specified command in the command variable as a child process with the user's full privileges, leading to remote code execution (RCE).
Recommendations Update to version 1.0.233.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45035
GHSA-HF8H-RJRF-3JG6

Affected Products

Tabby