Impact
Warp, an agentic development environment, allows a malicious actor to execute arbitrary commands on the underlying Windows system when operating under WSL. The vulnerability resides in the URL‑opening fallback mechanism: if Warp cannot open a link through wslview, it falls back to launching a Windows command processor path with the URL as an argument. A URL that is injected into terminal output can trigger this fallback, giving the attacker the ability to run any Windows command. This leads to a loss of confidentiality, integrity, and availability on the host machine.
Affected Systems
The affected product is warpdotdev:warp, versions ranging from 0.2024.03.12.08.02.stable_01 up to but excluding 0.2026.05.06.15.42.stable_01. Version 0.2026.05.06.15.42.stable_01 contains the fix. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, and the EPSS score is not available, but the likely attack vector is a user clicking a malicious link in terminal output while Warp is running in WSL. The vulnerability exploits a missing input validation (CWE‑116) and permits OS command injection (CWE‑78). Because no KEV listing exists, active exploitation may not have been observed yet, yet the impact is significant should the flaw be leveraged.
OpenCVE Enrichment