CVE-2026-54699
HIGHWarp: OS command injection when opening terminal links from WSL
Title source: cnaDescription
Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows command processor path. A URL controlled through terminal output can reach that fallback when the user opens the link. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/warpdotdev/warp/security/advisories/GHSA-xmw3-wj6r-48m4
X_Refsource_Misc x_refsource_misc
https://github.com/warpdotdev/warp/commit/c66cff48afba73bb1f26f82e5d524018bacb748e
Scores
CVSS v3
7.7
EPSS
0.0044
EPSS Percentile
34.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-116
CWE-78
Status
published
Products (1)
warpdotdev/warp
>= 0.2024.03.12.08.02.stable_01, < 0.2026.05.13.09.15.stable_01
Published
Jun 24, 2026
Tracked Since
Jun 24, 2026