What is CVE-2026-72903?
In Tabby terminal emulator (formerly Terminus) versions prior to 1.0.235, a malicious SFTP server can exploit a path traversal vulnerability using a backslash in `entry.name`. The `SFTPSession.readdir()` and `_makeFile()` functions in `tabby-ssh` module do not sanitize backslash characters properly, potentially allowing unauthorized file system operations. Users should immediately update to version 1.0.235 or later.
Azərbaycanca: Tabby terminal emulyatorunda (əvvəlki adı Terminus) 1.0.235-dən əvvəlki versiyalarda, zərərli SFTP server `entry.name` vasitəsilə `\` simvolu ilə path traversal həyata keçirə bilər. `tabby-ssh` modulundakı `SFTPSession.readdir()` və `_makeFile()` funksiyaları əks slesh simvolunu zərərsizləşdirmir, bu da fayl sistemi üzərində icazəsiz əməliyyatlara səbəb ola bilər. Təsirə məruz qalan istifadəçilər dərhal 1.0.235 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Tabby terminal emulator are vulnerable to CVE-2026-72903?
Versions of Tabby prior to 1.0.235 are affected by this vulnerability.
What action should be taken to mitigate CVE-2026-72903?
Users should immediately update Tabby to version 1.0.235 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.