CVE-2025-22136 Information
Jan 09, 2025
cve
Description
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 Tabby enables several high-risk Electron Fuses including RunAsNode EnableNodeCliInspectArguments and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection vectors even though the application is signed with hardened runtime and lacks dangerous entitlements such as com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables. This vulnerability is fixed in 1.0.217.
Reference
https://github.com/Eugeny/tabby/commit/93513541f7161fa8a59491603cabb6a101c0c08e https://github.com/Eugeny/tabby/security/advisories/GHSA-prcj-7rvc-26h4
Share on: