PT-2026-52034 · Warp · Warp

CVE-2026-54686

·

Published

2026-06-24

·

Updated

2026-06-25

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Warp versions 0.2021.04.25.23.05.stable 00 through 0.2026.05.06.15.42.stable 00
Description Warp accepts state-mutating terminal lifecycle hooks from the PTY (Pseudo-Terminal) stream without verifying if the hooks were emitted by the shell integration for the active session. An attacker capable of inducing a victim to view attacker-controlled terminal output can spoof lifecycle metadata, such as the current working directory for the active block or SSH session transport metadata.
Recommendations Update to version 0.2026.05.06.15.42.stable 01.

Exploit

Fix

Argument Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54686
GHSA-9W2V-JHWW-VM85

Affected Products

Warp