Vulnerability Description
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. An attacker who could cause a victim to view attacker-controlled terminal output in Warp could spoof selected lifecycle metadata, including the current working directory reported for the active block or SSH session transport metadata. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/warpdotdev/warp/commit/32d21d15c9a3da1a923d1ed66226cf5cba081d
- https://github.com/warpdotdev/warp/commit/51bd3267803c5cc0a45074fa19fd50162be7c9
- https://github.com/warpdotdev/warp/security/advisories/GHSA-9w2v-jhww-vm85
FAQ
What is CVE-2026-54686?
CVE-2026-54686 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream with...
How severe is CVE-2026-54686?
CVE-2026-54686 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54686?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.