CVE-2026-48731 Details
Description
Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the Linux external editor launcher. Warp expanded freedesktop .desktop Exec templates for affected editor integrations and executed the expanded command through a shell. A user who opens an attacker-controlled local file path through an affected external editor or system-default editor route can cause shell syntax embedded in that path to execute as the local user. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
A command injection vulnerability has been identified in Warp versions 0.2024.02.20.08.01.stable_01 prior to 0.2026.05.06.15.42.stable_01. The issue arises in the Linux external editor launcher, where Warp improperly executed expanded freedesktop .desktop Exec commands through a shell. This flaw allows a user to execute shell syntax embedded in an attacker-controlled file path as the local user, by opening the file with an affected external editor or the system-default editor.
Users are advised to update to Warp version 0.2026.05.06.15.42.stable_01 or later. Those on affected versions can avoid using the problematic external editor routes and open files directly within Warp.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/warpdotdev/warp/commit/861dacea2683f2fe263c3c3a1381c3cbb2b66809 | [email protected] | Source CodeVendor |
| https://github.com/warpdotdev/warp/security/advisories/GHSA-7xgc-mhc8-g7wc | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Warp | >= v0.2024.02.20.08.01.stable_01, <= v0.2026.05.06.15.42.stable_01 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion