Записи tabby
5 опубликованных записей вендора tabby.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences1
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2026-45035Эксплойта нет | Tabby: RCE via `tabby://run` URL Schemetabby · tabby · CWE-78 | Критическая9,4 | — | 0,5 % | 15 мая 2026 г. |
33Наблюдать | CVE-2026-45038Эксплойта нет | Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Executiontabby · tabby · CWE-150 | Высокая8,4 | — | 0,2 % | 15 мая 2026 г. |
31Наблюдать | CVE-2026-46709Эксплойта нет | Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)tabby · tabby · CWE-77 | Высокая7,8 | — | 0,3 % | 15 июл. 2026 г. |
28Наблюдать | CVE-2026-45037Эксплойта нет | Tabby: Unsafe protocol handler execution via terminal linkifier allows arbitrary OS protocol invocationtabby · tabby · CWE-184 | Высокая7,1 | — | 0,2 % | 15 мая 2026 г. |
28Наблюдать | CVE-2026-45036Эксплойта нет | Tabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zshtabby · tabby · CWE-78 | Высокая7,0 | — | 0,2 % | 15 мая 2026 г. |
- CVE-2026-4503537Наблюдать
Tabby: RCE via `tabby://run` URL Scheme
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %tabby · tabby15 мая 2026 г.
- CVE-2026-4503833Наблюдать
Tabby: Dragging and Dropping a File into Tabby Can Lead to Code Execution
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %tabby · tabby15 мая 2026 г.
- CVE-2026-4670931Наблюдать
Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %tabby · tabby15 июл. 2026 г.
- CVE-2026-4503728Наблюдать
Tabby: Unsafe protocol handler execution via terminal linkifier allows arbitrary OS protocol invocation
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %tabby · tabby15 мая 2026 г.
- CVE-2026-4503628Наблюдать
Tabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zsh
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %tabby · tabby15 мая 2026 г.