PT-2026-41320 · Tabby · Tabby
CVE-2026-45035
·
Published
2026-05-15
·
Updated
2026-05-19
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Tabby versions prior to 1.0.233
Description
Tabby registers itself as the handler for the
tabby:// URL scheme across all platforms. The handler supports a run command that executes operating system commands without user confirmation, sanitization, or sandboxing. An attacker can deliver a malicious link using the tabby://run?command=... format via websites, emails, or chat messages. When a user clicks the link, the application spawns the specified command in the command variable as a child process with the user's full privileges, leading to remote code execution (RCE).Recommendations
Update to version 1.0.233.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tabby