PT-2026-52028 · Warp · Warp
CVE-2026-48721
·
Published
2026-06-24
·
Updated
2026-06-25
CVSS v3.1
8.6
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Warp versions 0.2025.10.08.08.12.stable 00 through 0.2026.05.06.15.42.stable 00
Description
A command execution permission-check bypass exists in the default unsandboxed CLI agent profile. This profile is non-interactive and utilizes a command denylist to restrict commands that require confirmation. The issue occurs because command strings are checked before canonicalizing leading environment-variable assignments, allowing an attacker who can influence the agent's command output to execute denylisted commands by making them appear as non-denylisted.
Recommendations
Update to version 0.2026.05.06.15.42.stable 01.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Warp