Executive brief
Warp is a modern terminal and development environment. A vulnerability allowed malicious terminal output to trick the application into misidentifying session metadata, such as the current working directory or SSH connection details. If a user views specially crafted text (for example, by downloading a malicious file or connecting to a compromised server), it could cause the terminal to behave incorrectly or misrepresent the user's current environment, potentially leading to operational errors.
Technical details
Warp accepted state-mutating terminal lifecycle hooks (DCS hooks) from the PTY stream without verifying their origin. An attacker who can control terminal output viewed by a victim—such as through a malicious script, file content, or a compromised SSH session—can spoof lifecycle metadata. This includes the current working directory (CWD) and SSH session transport metadata. The root cause is a lack of integrity checks on hooks emitted by shell integrations. The fix introduces client-generated session IDs that must be registered and validated before Warp accepts state-mutating hooks. This vulnerability is addressed in version 0.2026.05.06.15.42.stable_01.
Affected products
- warpdotdev Warp >= 0.2021.04.25.23.05.stable_00, < 0.2026.05.06.15.42.stable_01
Timeline
- 2026-05-07: patched: Initial fix commit for DCS hook integrity checks
- 2026-06-09: advisory: GitHub Security Advisory GHSA-9w2v-jhww-vm85 published
- 2026-06-24: disclosed: CVE-2026-54686 published to NVD