CVE-2026-48704 Details
Description
Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system default file handler. A malicious Markdown document or project can contain a local-file link that appears as normal rendered content. If a user opens the Markdown in Warp and clicks the link, affected builds may route the resolved local file to a platform file opener instead of limiting the action to safe viewer/editor targets. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
A vulnerability in Warp's Markdown notebook link handling may lead to the execution of local files through the operating system's default file handler. This issue is present in Warp versions 0.2023.10.24.08.03.stable_00 prior to 0.2026.05.06.15.42.stable_01. The vulnerability arises because a malicious Markdown document can contain links to local files that, when clicked, are routed to the default file opener instead of being limited to safe viewer or editor options. This behavior could allow executable files, such as shell scripts without extensions, to be opened, potentially leading to arbitrary code execution.
Users can update to Warp version 0.2026.05.06.15.42.stable_01 or later, where this vulnerability has been fixed. If an immediate update is not possible, it is advisable to avoid clicking on links in Markdown files from untrusted sources.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/warpdotdev/warp/commit/7f0c4dd2322198f1b39890f8e6bcdc606c6a3c74 | [email protected] | Source CodeVendor |
| https://github.com/warpdotdev/warp/security/advisories/GHSA-589x-4mxh-jcrf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Warp | >= v0.2023.10.24.08.03.stable_00, < v0.2026.05.06.15.42.stable_01 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion