Executive brief
Warp is a modern terminal and development environment. A security flaw exists where clicking a malicious link displayed in the terminal while using Windows Subsystem for Linux (WSL) could allow an attacker to execute unauthorized commands on the host Windows computer. This could lead to a full system compromise or data theft if a user is tricked into interacting with a specially crafted URL.
Technical details
An OS command injection vulnerability (CWE-78) exists in Warp's WSL URL-opening fallback logic. When Warp is running under WSL and the 'wslview' utility is unavailable, the application falls back to a Windows command processor path to open URLs. This fallback mechanism fails to properly neutralize or escape special characters in the URL. An attacker can trigger this by outputting a malicious URL to the terminal; if the user clicks the link, the injected commands are executed on the Windows host with the privileges of the current user. The vulnerability is fixed in version 0.2026.05.13.09.15.stable_01 by implementing URL validation, restricting schemes to http/https, and replacing the command-processor fallback with a proper Windows URL handler invocation.
Affected products
- Warpdotdev Warp >= 0.2024.03.12.08.02.stable_01, < 0.2026.05.13.09.15.stable_01
Timeline
- 2026-06-09: advisory: GitHub security advisory published by vendor
- 2026-06-24: disclosed: CVE published to NVD