{"schema_version":1,"title":"Eugeny Tabby vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in Eugeny Tabby: 0 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-68930, was published on 3 August 2026.","url":"https://junglewise.ai/threats/technologies/tabby","json_url":"https://junglewise.ai/threats/technologies/tabby.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/tabby","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":13,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":12},"latest":[{"cve":"CVE-2026-68930","cvss":6.5,"slug":"cve-2026-68930-eugeny-russh-channel-scoped-callback-bypass-for-unopened-channels","title":"Eugeny Russh channel-scoped callback bypass for unopened channels","severity":"medium","exploited":false,"published_at":"2026-08-03T15:35:00+00:00","url":"https://junglewise.ai/threats/cve-2026-68930-eugeny-russh-channel-scoped-callback-bypass-for-unopened-channels"},{"cvss":5.3,"slug":"eugeny-russh-panic-in-curve25519-client-key-exchange-e8b8c834","title":"Eugeny Russh panic in Curve25519 client key exchange","severity":"medium","exploited":false,"published_at":"2026-07-24T16:47:16+00:00","url":"https://junglewise.ai/threats/eugeny-russh-panic-in-curve25519-client-key-exchange-e8b8c834"},{"cvss":4.3,"slug":"russh-denial-of-service-via-pty-req-terminal-mode-records-overflow-e75d300c","title":"Russh denial of service via pty-req terminal-mode records overflow","severity":"medium","exploited":false,"published_at":"2026-07-24T16:46:13+00:00","url":"https://junglewise.ai/threats/russh-denial-of-service-via-pty-req-terminal-mode-records-overflow-e75d300c"},{"cvss":5.3,"slug":"eugeny-russh-denial-of-service-via-all-zero-curve25519-public-value-6658ace7","title":"Eugeny Russh denial of service via all-zero Curve25519 public value","severity":"medium","exploited":false,"published_at":"2026-07-24T16:45:26+00:00","url":"https://junglewise.ai/threats/eugeny-russh-denial-of-service-via-all-zero-curve25519-public-value-6658ace7"},{"cve":"CVE-2026-46709","cvss":7.8,"slug":"cve-2026-46709-eugeny-tabby-os-command-injection-via-drag-and-drop-file-path","title":"Eugeny Tabby OS command injection via drag-and-drop file path","severity":"high","exploited":false,"published_at":"2026-07-15T16:16:46.053+00:00","url":"https://junglewise.ai/threats/cve-2026-46709-eugeny-tabby-os-command-injection-via-drag-and-drop-file-path"},{"cve":"CVE-2026-48108","cvss":5.3,"epss":0.0012,"slug":"cve-2026-48108-eugeny-russh-resource-exhaustion-in-ssh-identification-parsing","title":"Eugeny Russh resource exhaustion in SSH identification parsing","severity":"medium","exploited":false,"published_at":"2026-06-10T22:17:01.13+00:00","url":"https://junglewise.ai/threats/cve-2026-48108-eugeny-russh-resource-exhaustion-in-ssh-identification-parsing"},{"cve":"CVE-2026-46705","cvss":5.3,"slug":"cve-2026-46705-eugeny-russh-authentication-state-mismatch-in-ssh-server","title":"Eugeny Russh authentication state mismatch in SSH server","severity":"medium","exploited":false,"published_at":"2026-06-10T22:17:00.713+00:00","url":"https://junglewise.ai/threats/cve-2026-46705-eugeny-russh-authentication-state-mismatch-in-ssh-server"},{"cve":"CVE-2026-45038","cvss":8.4,"slug":"cve-2026-45038-eugeny-tabby-code-execution-via-drag-and-drop-control-characters","title":"Eugeny Tabby code execution via drag-and-drop control characters","severity":"info","exploited":false,"published_at":"2026-05-15T17:16:48.76+00:00","url":"https://junglewise.ai/threats/cve-2026-45038-eugeny-tabby-code-execution-via-drag-and-drop-control-characters"},{"cve":"CVE-2026-45037","cvss":7.1,"epss":0.0004,"slug":"cve-2026-45037-eugeny-tabby-unsafe-protocol-handler-execution-in-terminal","title":"Eugeny Tabby unsafe protocol handler execution in terminal linkifier","severity":"high","exploited":false,"published_at":"2026-05-15T17:16:48.623+00:00","url":"https://junglewise.ai/threats/cve-2026-45037-eugeny-tabby-unsafe-protocol-handler-execution-in-terminal"},{"cve":"CVE-2026-45036","cvss":7,"slug":"cve-2026-45036-eugeny-tabby-command-injection-via-zmodem-auto-confirmation","title":"Eugeny Tabby command injection via ZMODEM auto-confirmation","severity":"high","exploited":false,"published_at":"2026-05-15T17:16:48.487+00:00","url":"https://junglewise.ai/threats/cve-2026-45036-eugeny-tabby-command-injection-via-zmodem-auto-confirmation"},{"cve":"CVE-2026-45035","cvss":9.4,"slug":"cve-2026-45035-eugeny-tabby-os-command-injection-in-tabby-url-scheme","title":"Eugeny Tabby OS command injection in tabby:// URL scheme","severity":"info","exploited":false,"published_at":"2026-05-15T17:16:48.35+00:00","url":"https://junglewise.ai/threats/cve-2026-45035-eugeny-tabby-os-command-injection-in-tabby-url-scheme"},{"cve":"CVE-2026-42189","cvss":7.5,"slug":"cve-2026-42189-russh-ssh-library-denial-of-service-in-keyboard-interactive-auth","title":"Russh SSH library denial of service in keyboard-interactive auth","severity":"high","exploited":false,"published_at":"2026-05-08T20:16:31.443+00:00","url":"https://junglewise.ai/threats/cve-2026-42189-russh-ssh-library-denial-of-service-in-keyboard-interactive-auth"},{"cve":"CVE-2024-48460","cvss":4,"epss":0.0036,"slug":"cve-2024-48460-eugeny-tabby-credential-exposure-on-host-key-verification-failure","title":"Eugeny Tabby credential exposure on host key verification failure","severity":"medium","exploited":false,"published_at":"2025-01-17T00:30:48+00:00","url":"https://junglewise.ai/threats/cve-2024-48460-eugeny-tabby-credential-exposure-on-host-key-verification-failure"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Eugeny Tabby","slug":"tabby","vendor":{"name":"Eugeny","slug":"eugeny","url":"https://junglewise.ai/threats/vendors/eugeny"},"aliases":[],"category":"terminal-emulator","homepage":"https://tabby.sh/","repo_url":"https://github.com/Eugeny/tabby","description":"Tabby (formerly Terminus) is a highly configurable terminal emulator, SSH and serial client for Windows, macOS and Linux.","url":"https://junglewise.ai/threats/technologies/tabby"},"most_severe":[{"cve":"CVE-2026-46709","cvss":7.8,"slug":"cve-2026-46709-eugeny-tabby-os-command-injection-via-drag-and-drop-file-path","title":"Eugeny Tabby OS command injection via drag-and-drop file path","severity":"high","exploited":false,"published_at":"2026-07-15T16:16:46.053+00:00","url":"https://junglewise.ai/threats/cve-2026-46709-eugeny-tabby-os-command-injection-via-drag-and-drop-file-path"},{"cve":"CVE-2026-42189","cvss":7.5,"slug":"cve-2026-42189-russh-ssh-library-denial-of-service-in-keyboard-interactive-auth","title":"Russh SSH library denial of service in keyboard-interactive auth","severity":"high","exploited":false,"published_at":"2026-05-08T20:16:31.443+00:00","url":"https://junglewise.ai/threats/cve-2026-42189-russh-ssh-library-denial-of-service-in-keyboard-interactive-auth"},{"cve":"CVE-2026-45037","cvss":7.1,"epss":0.0004,"slug":"cve-2026-45037-eugeny-tabby-unsafe-protocol-handler-execution-in-terminal","title":"Eugeny Tabby unsafe protocol handler execution in terminal linkifier","severity":"high","exploited":false,"published_at":"2026-05-15T17:16:48.623+00:00","url":"https://junglewise.ai/threats/cve-2026-45037-eugeny-tabby-unsafe-protocol-handler-execution-in-terminal"},{"cve":"CVE-2026-45036","cvss":7,"slug":"cve-2026-45036-eugeny-tabby-command-injection-via-zmodem-auto-confirmation","title":"Eugeny Tabby command injection via ZMODEM auto-confirmation","severity":"high","exploited":false,"published_at":"2026-05-15T17:16:48.487+00:00","url":"https://junglewise.ai/threats/cve-2026-45036-eugeny-tabby-command-injection-via-zmodem-auto-confirmation"},{"cve":"CVE-2026-68930","cvss":6.5,"slug":"cve-2026-68930-eugeny-russh-channel-scoped-callback-bypass-for-unopened-channels","title":"Eugeny Russh channel-scoped callback bypass for unopened channels","severity":"medium","exploited":false,"published_at":"2026-08-03T15:35:00+00:00","url":"https://junglewise.ai/threats/cve-2026-68930-eugeny-russh-channel-scoped-callback-bypass-for-unopened-channels"},{"cve":"CVE-2026-48108","cvss":5.3,"epss":0.0012,"slug":"cve-2026-48108-eugeny-russh-resource-exhaustion-in-ssh-identification-parsing","title":"Eugeny Russh resource exhaustion in SSH identification parsing","severity":"medium","exploited":false,"published_at":"2026-06-10T22:17:01.13+00:00","url":"https://junglewise.ai/threats/cve-2026-48108-eugeny-russh-resource-exhaustion-in-ssh-identification-parsing"},{"cvss":5.3,"slug":"eugeny-russh-panic-in-curve25519-client-key-exchange-e8b8c834","title":"Eugeny Russh panic in Curve25519 client key exchange","severity":"medium","exploited":false,"published_at":"2026-07-24T16:47:16+00:00","url":"https://junglewise.ai/threats/eugeny-russh-panic-in-curve25519-client-key-exchange-e8b8c834"},{"cvss":5.3,"slug":"eugeny-russh-denial-of-service-via-all-zero-curve25519-public-value-6658ace7","title":"Eugeny Russh denial of service via all-zero Curve25519 public value","severity":"medium","exploited":false,"published_at":"2026-07-24T16:45:26+00:00","url":"https://junglewise.ai/threats/eugeny-russh-denial-of-service-via-all-zero-curve25519-public-value-6658ace7"},{"cve":"CVE-2026-46705","cvss":5.3,"slug":"cve-2026-46705-eugeny-russh-authentication-state-mismatch-in-ssh-server","title":"Eugeny Russh authentication state mismatch in SSH server","severity":"medium","exploited":false,"published_at":"2026-06-10T22:17:00.713+00:00","url":"https://junglewise.ai/threats/cve-2026-46705-eugeny-russh-authentication-state-mismatch-in-ssh-server"},{"cvss":4.3,"slug":"russh-denial-of-service-via-pty-req-terminal-mode-records-overflow-e75d300c","title":"Russh denial of service via pty-req terminal-mode records overflow","severity":"medium","exploited":false,"published_at":"2026-07-24T16:46:13+00:00","url":"https://junglewise.ai/threats/russh-denial-of-service-via-pty-req-terminal-mode-records-overflow-e75d300c"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}