Junglewise Threat Intelligence

CVE-2026-54699: Warp OS command injection in WSL URL-opening fallback

CVE-2026-54699 · Severity: high · CVSS 7.7 · Published 2026-06-24

Technologies: Warpdotdev WARP.

Executive brief

Warp is a modern terminal and development environment. A security flaw exists where clicking a malicious link displayed in the terminal while using Windows Subsystem for Linux (WSL) could allow an attacker to execute unauthorized commands on the host Windows computer. This could lead to a full system compromise or data theft if a user is tricked into interacting with a specially crafted URL.

Technical details

An OS command injection vulnerability (CWE-78) exists in Warp's WSL URL-opening fallback logic. When Warp is running under WSL and the 'wslview' utility is unavailable, the application falls back to a Windows command processor path to open URLs. This fallback mechanism fails to properly neutralize or escape special characters in the URL. An attacker can trigger this by outputting a malicious URL to the terminal; if the user clicks the link, the injected commands are executed on the Windows host with the privileges of the current user. The vulnerability is fixed in version 0.2026.05.13.09.15.stable_01 by implementing URL validation, restricting schemes to http/https, and replacing the command-processor fallback with a proper Windows URL handler invocation.

Affected products

  • Warpdotdev Warp >= 0.2024.03.12.08.02.stable_01, < 0.2026.05.13.09.15.stable_01

Timeline

  • 2026-06-09: advisory: GitHub security advisory published by vendor
  • 2026-06-24: disclosed: CVE published to NVD

References