{"api_version":"v1","generated_at":"2026-10-06T16:55:00+00:00","product":{"cve_count":8,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-eugeny-tabby-3caf47d6efec","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/tabby","name":"tabby","next_cursor":null,"observations":[{"affected":"< 1.0.235","affected_versions_present":true,"cve_id":"CVE-2026-72903","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-72903","fixed":"1.0.235.","last_modified":"2026-08-11T14:57:24.700Z","patch_url":"https://github.com/Eugeny/tabby/security/advisories/GHSA-59p9-8gwf-v9v7","primary_source":"","published":"2026-08-10T20:39:57.054Z"},{"affected":"< 1.0.234","affected_versions_present":true,"cve_id":"CVE-2026-46709","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-46709","fixed":"1.0.234.","last_modified":"2026-07-16T03:55:43.215Z","patch_url":"https://github.com/Eugeny/tabby/commit/e151472b951bbd472ddc0545ec8656e4c0f352da","primary_source":"","published":"2026-07-15T14:59:18.601Z"},{"affected":"< 1.0.233","affected_versions_present":true,"cve_id":"CVE-2026-45038","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45038","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-20T15:42:12.319Z","patch_url":"","primary_source":"","published":"2026-05-15T16:48:12.110Z"},{"affected":"< 1.0.233","affected_versions_present":true,"cve_id":"CVE-2026-45036","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45036","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-20T15:42:57.726Z","patch_url":"https://github.com/Eugeny/tabby/security/advisories/GHSA-qr3x-j8g9-xhf6","primary_source":"","published":"2026-05-15T16:47:17.974Z"},{"affected":"< 1.0.233","affected_versions_present":true,"cve_id":"CVE-2026-45035","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45035","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-21T03:55:17.500Z","patch_url":"","primary_source":"","published":"2026-05-15T16:41:11.422Z"},{"affected":"< 1.0.232","affected_versions_present":true,"cve_id":"CVE-2026-45037","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45037","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-15T17:49:42.531Z","patch_url":"https://github.com/Eugeny/tabby/security/advisories/GHSA-cmpc-v2x9-j9x9","primary_source":"","published":"2026-05-15T16:40:10.317Z"},{"affected":"< 1.0.217","affected_versions_present":true,"cve_id":"CVE-2025-22136","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-22136","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-01-08T19:25:39.232Z","patch_url":"","primary_source":"","published":"2025-01-08T16:02:01.460Z"},{"affected":"< 1.0.216","affected_versions_present":true,"cve_id":"CVE-2024-55950","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-55950","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-27T16:17:59.385Z","patch_url":"","primary_source":"","published":"2024-12-26T21:52:44.619Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Eugeny"}}
