Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Warp: Command Injection via Warp code search tool arguments
Vulnerability Description
Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution policy bypass in Agent code search tools. The affected Grep and FileGlob actions are authorized as read/search operations, but their implementations build shell command strings from Agent-controlled inputs (search text, paths, glob patterns) and execute them in the active terminal session. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Warp 命令注入漏洞
Vulnerability Description
Warp是Warp公司开源的一个远程管理软件。 Warp 0.2025.04.09.08.11.stable_00版本至0.2026.05.06.15.42.stable_01版本存在命令注入漏洞,该漏洞源于Agent代码搜索工具在执行命令时构建shell命令字符串,可能导致命令执行策略绕过。
CVSS Information
N/A
Vulnerability Type
N/A