CVE-2026-48725 Details
Description
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system clipboard. A malicious remote host, remote program, or other attacker-controlled terminal output source can trigger clipboard reads or writes without a separate confirmation step. This crosses the trust boundary between untrusted terminal output and the user's local desktop clipboard. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
A vulnerability in Warp, an agentic development environment, allows terminal output to access the local system clipboard without user confirmation. This issue affects Warp versions from 0.2021.04.25.23.05.stable_00 to 0.2026.05.06.15.42.stable_01. The vulnerability enables a malicious remote host, program, or attacker-controlled terminal output source to read or write clipboard contents, crossing the trust boundary between untrusted terminal output and the user's desktop clipboard.
Users are advised to update to Warp version 0.2026.05.06.15.42.stable_01, where this vulnerability has been patched. The update disables clipboard access via OSC 52 by default, preventing any read or write operations. Instructions for updating can be found in the Warp repository on GitHub.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/warpdotdev/warp/commit/b1a41d0b1aba9f40db1e5ceb695183452a894003 | [email protected] | Source CodeVendor |
| https://github.com/warpdotdev/warp/security/advisories/GHSA-wgqj-4c26-7c4g | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-276 | Incorrect Default Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Warp | >= v0.2021.04.25.23.05.stable_00, <= v0.2026.05.06.15.42.stable_01 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion