Vulnerability Description
Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system default file handler. A malicious Markdown document or project can contain a local-file link that appears as normal rendered content. If a user opens the Markdown in Warp and clicks the link, affected builds may route the resolved local file to a platform file opener instead of limiting the action to safe viewer/editor targets. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/warpdotdev/warp/commit/7f0c4dd2322198f1b39890f8e6bcdc606c6a3c
- https://github.com/warpdotdev/warp/security/advisories/GHSA-589x-4mxh-jcrf
FAQ
What is CVE-2026-48704?
CVE-2026-48704 is a vulnerability with a CVSS score of 8.8 (HIGH). Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system default file handler...
How severe is CVE-2026-48704?
CVE-2026-48704 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48704?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.