CVE-2026-54686 Details
Description
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. An attacker who could cause a victim to view attacker-controlled terminal output in Warp could spoof selected lifecycle metadata, including the current working directory reported for the active block or SSH session transport metadata. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
A vulnerability in Warp, an agentic development environment, allows for the spoofing of terminal lifecycle metadata. This issue is present in Warp versions 0.2021.04.25.23.05.stable_00 through 0.2026.05.06.15.42.stable_01. The vulnerability arises because Warp accepted certain state-mutating lifecycle hooks from the PTY stream without verifying their origin. An attacker could exploit this by causing a victim to view manipulated terminal output, thereby altering the reported current working directory or SSH session transport metadata. The vulnerability is fixed in Warp version 0.2026.05.06.15.42.stable_01.
Users can update to Warp version 0.2026.05.06.15.42.stable_01 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/warpdotdev/warp/commit/32d21d15c9a3da1a923d1ed66226cf5cba081d16 | [email protected] | Source CodeVendor |
| https://github.com/warpdotdev/warp/commit/51bd3267803c5cc0a45074fa19fd50162be7c917 | [email protected] | Source CodeVendor |
| https://github.com/warpdotdev/warp/security/advisories/GHSA-9w2v-jhww-vm85 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Warp | >v0.2021.04.25.23.05.stable_00, < v0.2026.05.06.15.42.stable_01 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion