PT-2026-52035 · Warpdotdev · Warp
Published
2026-06-24
·
Updated
2026-06-24
·
CVE-2026-54699
CVSS v3.1
7.7
High
| Vector | AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Warp is an agentic development environment. From 0.2024.03.12.08.02.stable 01 until 0.2026.05.06.15.42.stable 01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows command processor path. A URL controlled through terminal output can reach that fallback when the user opens the link. This vulnerability is fixed in 0.2026.05.06.15.42.stable 01.
Fix
Improper Encoding or Escaping of Output
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Warp