CVE-2026-48719 Details
Description
Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish a branch to a Git repository opened in Warp can cause a crafted branch name to be interpreted by the victim's shell if the victim selects that branch from the UI. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
A command injection vulnerability has been identified in the Warp development environment, specifically in versions 0.2025.08.06.08.12.stable_00 prior to 0.2026.05.06.15.42.stable_01. The issue arises in the prompt branch selector, where a user who can publish a branch to a Git repository opened in Warp can craft a branch name that, when selected by another user, is executed in their shell. This vulnerability allows for arbitrary command execution with the affected user's local shell privileges.
Users should update to Warp version 0.2026.05.06.15.42.stable_01 or later. If an immediate update is not possible, avoid using the branch selector in repositories where untrusted users can publish branches.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/warpdotdev/warp/commit/4295ec08d01912fe355351547e541277f29288cd | [email protected] | Source CodeVendor |
| https://github.com/warpdotdev/warp/security/advisories/GHSA-hgvx-4xvm-39pw | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Warp | >= v0.2025.08.06.08.12.stable_00, < v0.2026.05.06.15.42.stable_01 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion