Executive brief
Tabby is a terminal emulator used by developers and system administrators to interact with command-line interfaces. A vulnerability in how it handles file transfer protocols allows an attacker to execute malicious commands on a user's computer if the user views a specially crafted file (for example, using the 'cat' command). This could lead to a full system compromise or data theft simply by the user inspecting the contents of a malicious file or repository.
Technical details
The vulnerability exists in the ZModemMiddleware component of tabby-terminal, which monitors session output for ZMODEM ZRQINIT headers. When a header is detected, the middleware unconditionally calls detection.confirm() and writes a fixed ZRINIT response back into the active pseudo-terminal (PTY) as input without user interaction. If a user 'cats' a malicious file, these injected bytes are buffered and then executed by the shell (fish, bash, or zsh) once the initial process exits. Attackers can use glob expansion (e.g., '**') or terminal color-query feedback (OSC 10) to construct a command path that executes a local malicious binary, bypassing PATH restrictions. The issue is fixed in version 1.0.233.
Affected products
- Eugeny Tabby < 1.0.233
Timeline
- 2026-05-07: advisory: GitHub advisory published by maintainer
- 2026-05-15: disclosed: CVE published to NVD