CVE-2026-48719
HIGHWarp branch selector command injection via Git branch names
Title source: cnaDescription
Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish a branch to a Git repository opened in Warp can cause a crafted branch name to be interpreted by the victim's shell if the victim selects that branch from the UI. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/warpdotdev/warp/security/advisories/GHSA-hgvx-4xvm-39pw
X_Refsource_Misc x_refsource_misc
https://github.com/warpdotdev/warp/commit/4295ec08d01912fe355351547e541277f29288cd
Scores
CVSS v3
8.0
EPSS
0.0095
EPSS Percentile
56.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
warpdotdev/warp
>= 0.2025.08.06.08.12.stable_00, < 0.2026.05.13.09.15.stable_01
Published
Jun 24, 2026
Tracked Since
Jun 24, 2026