PT-2026-52035 · Warpdotdev · Warp

Published

2026-06-24

·

Updated

2026-06-24

·

CVE-2026-54699

CVSS v3.1

7.7

High

VectorAV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Warp is an agentic development environment. From 0.2024.03.12.08.02.stable 01 until 0.2026.05.06.15.42.stable 01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows command processor path. A URL controlled through terminal output can reach that fallback when the user opens the link. This vulnerability is fixed in 0.2026.05.06.15.42.stable 01.

Fix

Improper Encoding or Escaping of Output

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54699

Affected Products

Warp