CVE-2026-54686

Source
https://cve.org/CVERecord?id=CVE-2026-54686
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54686.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54686
Aliases
  • GHSA-9w2v-jhww-vm85
Published
2026-06-24T17:28:12.027Z
Modified
2026-07-15T01:49:17.804608428Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Warp: DCS lifecycle hook spoofing can alter terminal session metadata
Details

Warp is an agentic development environment. From 0.2021.04.25.23.05.stable00 until 0.2026.05.06.15.42.stable01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. An attacker who could cause a victim to view attacker-controlled terminal output in Warp could spoof selected lifecycle metadata, including the current working directory reported for the active block or SSH session transport metadata. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.

Database specific
{
    "cwe_ids": [
        "CWE-78",
        "CWE-88"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54686.json",
    "cna_assigner": "GitHub_M",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": ">= 0.2021.04.25.23.05.stable_00, < 0.2026.05.13.09.15.stable_01"
                },
                {
                    "last_affected": ">= 0.2021.04.25.23.05.stable_00, < 0.2026.05.13.09.15.stable_01"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/warpdotdev/warp

Affected ranges

Type
GIT
Repo
https://github.com/warpdotdev/warp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

Other
repo-sync/watermark/private-to-public
v0.*
v0.2026.04.29.08.56.preview_00
v0.2026.04.29.08.56.stable_00
v0.2026.04.29.08.57.dev_00
v0.2026.04.30.08.57.dev_00
v0.2026.05.01.08.50.dev_00
v0.2026.05.02.08.40.dev_00
v0.2026.05.03.08.43.dev_00
v0.2026.05.04.09.01.dev_00
v0.2026.05.05.08.57.dev_00
v0.2026.05.06.09.12.dev_00
v0.2026.05.06.09.12.stable_00
v0.2026.05.06.09.13.preview_00
v0.2026.05.07.09.05.dev_00
v0.2026.05.08.08.43.dev_00
v0.2026.05.09.08.42.dev_00
v0.2026.05.10.08.45.dev_00
v0.2026.05.11.09.24.dev_00
v0.2026.05.12.09.09.dev_00
v0.2026.05.13.09.14.stable_00
v0.2026.05.13.09.15.dev_00
v0.2026.05.13.09.15.preview_00
v0.2026.05.14.09.08.dev_00
v0.2026.05.15.09.17.dev_00
v0.2026.05.16.08.43.dev_00
v0.2026.05.17.08.52.dev_00
v0.2026.05.18.09.26.dev_00
v0.2026.05.19.09.24.dev_00
v0.2026.05.20.09.21.dev_00
v0.2026.05.20.09.21.preview_00
v0.2026.05.20.09.21.stable_00
v0.2026.05.21.09.21.dev_00
v0.2026.05.22.09.18.dev_00
v0.2026.05.23.08.51.dev_00
v0.2026.05.24.09.01.dev_00
v0.2026.05.25.09.34.dev_00
v0.2026.05.26.09.25.dev_00
v0.2026.05.27.09.22.dev_00
v0.2026.05.27.09.22.preview_00
v0.2026.05.27.09.22.stable_00
v0.2026.05.28.09.29.dev_00
v0.2026.05.29.09.24.dev_00
v0.2026.05.30.08.57.dev_00
v0.2026.05.31.09.13.dev_00
v0.2026.06.01.10.01.dev_00
v0.2026.06.02.09.40.dev_00
v0.2026.06.03.09.49.dev_00
v0.2026.06.03.09.49.preview_00
v0.2026.06.03.09.49.stable_00
v0.2026.06.04.09.31.dev_00
v0.2026.06.05.09.22.dev_00
v0.2026.06.06.09.03.dev_00
v0.2026.06.07.09.13.dev_00
v0.2026.06.08.09.48.dev_00
v0.2026.06.09.09.21.dev_00

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54686.json"