CVE 4.3 MEDIUM

Warp: DCS lifecycle hook spoofing can alter terminal session metadata_CVE-2026-54686

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Description

Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. An attacker who could cause a victim to view attacker-controlled terminal output in Warp could spoof selected lifecycle metadata, including the current working directory reported for the active block or SSH session transport metadata. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.

Basic Information

ID CVE-2026-54686
Source GitHub_M
Published Jun 24, 2026 at 17:28

Affected Product

Vendor warpdotdev
Product warp
Version >= 0.2021.04.25.23.05.stable_00, < 0.2026.05.13.09.15.stable_01
Affected Versions warpdotdev warp >= 0.2021.04.25.23.05.stable_00, < 0.2026.05.13.09.15.stable_01

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.