CVE-2026-48704

Source
https://cve.org/CVERecord?id=CVE-2026-48704
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48704.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48704
Aliases
  • GHSA-589x-4mxh-jcrf
Published
2026-06-24T17:35:02.730Z
Modified
2026-07-15T01:49:21.453071952Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Warp Markdown notebook links may open executable local files
Details

Warp is an agentic development environment. From 0.2023.10.24.08.03.stable00 until 0.2026.05.06.15.42.stable01, Warp may open executable local files through the operating system default file handler. A malicious Markdown document or project can contain a local-file link that appears as normal rendered content. If a user opens the Markdown in Warp and clicks the link, affected builds may route the resolved local file to a platform file opener instead of limiting the action to safe viewer/editor targets. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.

Database specific
{
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48704.json",
    "cna_assigner": "GitHub_M",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": ">= 0.2023.10.24.08.03.stable_00, < 0.2026.05.13.09.15.stable_01"
                },
                {
                    "last_affected": ">= 0.2023.10.24.08.03.stable_00, < 0.2026.05.13.09.15.stable_01"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/warpdotdev/warp

Affected ranges

Type
GIT
Repo
https://github.com/warpdotdev/warp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

Other
repo-sync/watermark/private-to-public
v0.*
v0.2026.04.29.08.56.preview_00
v0.2026.04.29.08.56.stable_00
v0.2026.04.29.08.57.dev_00
v0.2026.04.30.08.57.dev_00
v0.2026.05.01.08.50.dev_00
v0.2026.05.02.08.40.dev_00
v0.2026.05.03.08.43.dev_00
v0.2026.05.04.09.01.dev_00
v0.2026.05.05.08.57.dev_00
v0.2026.05.06.09.12.dev_00
v0.2026.05.06.09.12.stable_00
v0.2026.05.06.09.13.preview_00
v0.2026.05.07.09.05.dev_00
v0.2026.05.08.08.43.dev_00
v0.2026.05.09.08.42.dev_00
v0.2026.05.10.08.45.dev_00
v0.2026.05.11.09.24.dev_00
v0.2026.05.12.09.09.dev_00
v0.2026.05.13.09.14.stable_00
v0.2026.05.13.09.15.dev_00
v0.2026.05.13.09.15.preview_00
v0.2026.05.14.09.08.dev_00
v0.2026.05.15.09.17.dev_00
v0.2026.05.16.08.43.dev_00
v0.2026.05.17.08.52.dev_00
v0.2026.05.18.09.26.dev_00
v0.2026.05.19.09.24.dev_00
v0.2026.05.20.09.21.dev_00
v0.2026.05.20.09.21.preview_00
v0.2026.05.20.09.21.stable_00
v0.2026.05.21.09.21.dev_00
v0.2026.05.22.09.18.dev_00
v0.2026.05.23.08.51.dev_00
v0.2026.05.24.09.01.dev_00
v0.2026.05.25.09.34.dev_00
v0.2026.05.26.09.25.dev_00
v0.2026.05.27.09.22.dev_00
v0.2026.05.27.09.22.preview_00
v0.2026.05.27.09.22.stable_00
v0.2026.05.28.09.29.dev_00
v0.2026.05.29.09.24.dev_00
v0.2026.05.30.08.57.dev_00
v0.2026.05.31.09.13.dev_00
v0.2026.06.01.10.01.dev_00
v0.2026.06.02.09.40.dev_00
v0.2026.06.03.09.49.dev_00
v0.2026.06.03.09.49.preview_00
v0.2026.06.03.09.49.stable_00
v0.2026.06.04.09.31.dev_00
v0.2026.06.05.09.22.dev_00
v0.2026.06.06.09.03.dev_00
v0.2026.06.07.09.13.dev_00
v0.2026.06.08.09.48.dev_00
v0.2026.06.09.09.21.dev_00

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48704.json"