Multiple command injection and policy bypass flaws in Warp agentic dev environment
Seven CVEs disclosed against Warp, an agentic development environment, covering command execution policy and permission-check bypasses in its agent tools, command injection in branch selector, Linux editor launcher and legacy SSH paths, unconfirmed local file writes via OSC 1337 payloads, clipboard access from terminal output, and opening executable local files from Markdown links. All were fixed in release 0.2026.05.06.15.42.stable_01.
Disclosed 24 June 2026 · Record updated 13 September 2026
Impact
Attacker-influenced input (search terms, branch names, file paths, terminal output, remote directory names) could execute shell commands as the local user or on a remote SSH host, write local files, or read/write the desktop clipboard, bypassing Warp's command confirmation and denylist safeguards.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48703
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48704
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48719
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48720
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48721
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48725
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48731
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48732
