CVE-2026-54699 Details
Description
Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows command processor path. A URL controlled through terminal output can reach that fallback when the user opens the link. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
A command injection vulnerability has been identified in Warp versions 0.2024.03.12.08.02.stable_01 prior to 0.2026.05.06.15.42.stable_01. This vulnerability occurs when Warp is running under Windows Subsystem for Linux (WSL) and cannot open a URL using 'wslview'. In such cases, it falls back to a Windows command processor, where a URL controlled through terminal output can be exploited by the user opening the link. Successful exploitation may allow commands to be executed on the Windows host as the current user.
Users should update to Warp version 0.2026.05.13.09.15.stable_01 or later. If immediate updating is not possible, 'wslview' can be installed or the environment variable 'WARP_FORCE_WSL_BROWSER' can be set to '1' to prevent the Windows fallback.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 24, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/warpdotdev/warp/commit/c66cff48afba73bb1f26f82e5d524018bacb748e | [email protected] | Source CodeVendor |
| https://github.com/warpdotdev/warp/security/advisories/GHSA-xmw3-wj6r-48m4 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Warp | >= v0.2024.03.12.08.02.stable_01, <= v0.2026.05.06.15.42.stable_01 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |
Volerion