A vulnerability was found in Eugeny Tabby up to 1.0.234. It has been rated as critical. The impacted element is the function SFTPSession.readdir of the file tabby-ssh/src/session/sftp.ts of the component SFTP Handler. Performing a manipulation of the argument Name results in relative path traversal.

This vulnerability was named CVE-2026-72903. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.