Junglewise Threat Intelligence

CVE-2026-48719: Warp command injection in prompt branch selector

CVE-2026-48719 · Severity: high · CVSS 8 · Published 2026-06-24

Technologies: Warpdotdev WARP.

Executive brief

Warp is a modern terminal and development environment. A security flaw in its branch selection tool allows an attacker to execute malicious commands on a user's computer if the user interacts with a specially named Git branch. This could lead to full system compromise, data theft, or unauthorized access to the user's local files and development environment.

Technical details

A command injection vulnerability exists in Warp's prompt branch selector component due to improper neutralization of special elements in Git branch names. An attacker with the ability to publish branches to a repository can craft a branch name containing shell metacharacters. When a victim opens the repository in Warp and selects the malicious branch via the UI, the crafted name is interpreted by the victim's local shell. This allows for Remote Code Execution (RCE) with the privileges of the local user. The fix involves replacing command strings with typed command intents and implementing proper shell argument quoting (shell_quote_arg) before execution.

Affected products

  • warpdotdev Warp >= 0.2025.08.06.08.12.stable_00, < 0.2026.05.06.15.42.stable_01

Timeline

  • 2026-05-06: patched: Fix committed to repository
  • 2026-06-09: advisory: GitHub Security Advisory published
  • 2026-06-24: disclosed: CVE published to NVD

References