An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| tabby-ssh(npm) | 0 | 1.0.214 | N/A |
CVSS Metrics