CVE-2026-45037
CVE-2026-45037 is a high-severity vulnerability in Tabby with a CVSS 3.x base score of 7.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-184.
Key facts
- Severity: High (CVSS 3.x base score 7.1)
- EPSS exploit prediction: 0% (13th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-30569
- Weakness: CWE-184
- Affected product: Tabby
- Published:
- Last modified:
Description
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without validating the protocol scheme. This allows a malicious SSH or Telnet server to send crafted terminal output containing dangerous protocol URIs which Tabby renders as clickable links, triggering arbitrary OS protocol handlers on the victim's machine. This vulnerability is fixed in 1.0.232.
Frequently asked questions
- What is CVE-2026-45037?
- Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passes any detected URI directly to the operating system's protocol handler without validating the protocol scheme. This allows a malicious SSH or Telnet server to send crafted terminal output containing dangerous protocol URIs which Tabby renders as clickable links, triggering arbitrary OS protocol handlers on the victim's machine. This vulnerability is fixed in 1.0.232.
- How severe is CVE-2026-45037?
- CVE-2026-45037 has a CVSS 3.x base score of 7.1, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-45037 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (13th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-45037?
- CVE-2026-45037 affects Tabby. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-45037?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-45037 have an EU (EUVD) identifier?
- Yes. CVE-2026-45037 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-30569.
- When was CVE-2026-45037 published?
- CVE-2026-45037 was published on 2026-05-15 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:tabby:tabby:*:*:*:*:*:*:*:*
More vulnerabilities in Tabby
- CVE-2026-45035 — High (CVSS 8.8): Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the…
- CVE-2026-46709 — High (CVSS 7.8): Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file…
- CVE-2026-45038 — High (CVSS 7.8): Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape…
- CVE-2026-45036 — High (CVSS 7.0): Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233…
Other CWE-184 vulnerabilities
- CVE-2026-87985 — Critical (CVSS 10.0): An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using…
- CVE-2026-79696 — Critical (CVSS 10.0): A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through…
- CVE-2026-57138 — Critical (CVSS 9.9): PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in…
- CVE-2026-65083 — Critical (CVSS 9.9): NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an…
- CVE-2026-47392 — Critical (CVSS 9.9): PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of…
- CVE-2026-28363 — Critical (CVSS 9.9): In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option…