CVE-2025-22136

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection vectors even though the application is signed with hardened runtime and lacks dangerous entitlements such as com.apple.security.cs.disable-library-validation and com.apple.security.cs.allow-dyld-environment-variables. This vulnerability is fixed in 1.0.217.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Tabby (anteriormente Terminus) es un emulador de terminal altamente configurable. Antes de la versión 1.0.217, Tabby habilita varios fusibles Electron de alto riesgo, incluidos RunAsNode, EnableNodeCliInspectArguments y EnableNodeOptionsEnvironmentVariable. Estos fusibles crean posibles vectores de inyección de código a pesar de que la aplicación está firmada con un entorno de ejecución reforzado y carece de derechos peligrosos como com.apple.security.cs.disable-library-validation y com.apple.security.cs.allow-dyld-environment-variables. Esta vulnerabilidad se solucionó en la versión 1.0.217.

08 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-08 16:15

Updated : 2026-06-17 08:45


NVD link : CVE-2025-22136

Mitre link : CVE-2025-22136

CVE.ORG link : CVE-2025-22136


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')