VYPR
Medium severity4.3NVD Advisory· Published Jan 16, 2025· Updated Apr 15, 2026

CVE-2024-48460

CVE-2024-48460

Description

An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tabby-sshnpm
< 1.0.2141.0.214

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.