{"id":"CVE-2026-72903","title":"Tabby (formerly Terminus) is a highly configurable terminal emulator","summary":"Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _ma…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","cwe":["CWE-22"],"published":"2026-08-10","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:55:04.493","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72903","references":[{"url":"https://github.com/Eugeny/tabby/commit/3a4a41431a61d41dd51d4119e60cad9bf13c3399","label":"security-advisories@github.com"},{"url":"https://github.com/Eugeny/tabby/releases/tag/v1.0.235","label":"security-advisories@github.com"},{"url":"https://github.com/Eugeny/tabby/security/advisories/GHSA-59p9-8gwf-v9v7","label":"security-advisories@github.com"},{"url":"https://github.com/Eugeny/tabby/security/advisories/GHSA-59p9-8gwf-v9v7","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-72903.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-72903"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2513684"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72903"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72903"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00366,"epssPercentile":0.30463,"ingestedAt":"2026-09-09T21:22:45.526Z","vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4","affected":["openshift_data_foundation 4"],"slug":"CVE-2026-72903","body":"## Overview\n\nTabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslashes as ordinary filename characters. In tabby-ssh/src/components/sftpPanel.component.ts, downloadFolderRecursive() propagates item.name into the local relative path. In tabby-electron/src/services/platform.service.ts, ElectronDirectoryDownload.createFile() passes that path to Windows-native path.join(), and in tabby-electron/src/sftpContextMenu.ts, EditSFTPContextMenu.edit() passes item.name to path.join() for the temporary edit path. Windows interprets the preserved backslashes and parent-directory components as traversal, allowing attacker-controlled content to be created or overwritten outside the selected download directory or temporary edit directory. This issue is fixed in version 1.0.235.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Openshift Data Foundation 4 · no fix planned: Red Hat Openshift Data Foundation 4 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-72903.json)","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}