CVE-2026-48720
HIGHWarp: SSH remote output can lead to local file overwrite and persistence
Title source: cnaDescription
Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and materialize the decoded payload as a local file without an additional confirmation step. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/warpdotdev/warp/security/advisories/GHSA-5h96-jrrq-6hxq
X_Refsource_Misc x_refsource_misc
https://github.com/warpdotdev/warp/commit/f3b9ce1c8fd13d037526c447418d809087722daa
Scores
CVSS v3
8.8
EPSS
0.0025
EPSS Percentile
15.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-20
CWE-73
Status
published
Products (1)
warpdotdev/warp
>= 0.2025.03.05.08.02.stable_00, < 0.2026.05.13.09.15.stable_01
Published
Jun 24, 2026
Tracked Since
Jun 24, 2026