A vulnerability was found in Eugeny Tabby up to 1.0.234. It has been rated as critical. The impacted element is the function
SFTPSession.readdir of the file tabby-ssh/src/session/sftp.ts of the component SFTP Handler. Performing a manipulation of the argument Name results in relative path traversal.
This vulnerability was named CVE-2026-72903. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.