
Found a command injection vulnerability in Tabby's drag-and-drop functionality, similar to the one I found in a few other terminal emulators. This one is now tracked as CVE-2026-45038. https://github.com/Eugeny/tabby/security/advisories/GHSA-m937-jm93-pfp6 https://t.co/8eSslLsGRu
Post summary
Disclosed a command injection flaw in Tabby’s drag‑and‑drop feature (CVE-2026-45038); the post does not mention a PoC, exploit, patch, or active exploitation.
