Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Warp branch selector command injection via Git branch names
Vulnerability Description
Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish a branch to a Git repository opened in Warp can cause a crafted branch name to be interpreted by the victim's shell if the victim selects that branch from the UI. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Warp 命令注入漏洞
Vulnerability Description
Warp是Warp公司开源的一个远程管理软件。 Warp 0.2025.08.06.08.12.stable_00版本至0.2026.05.06.15.42.stable_01版本存在命令注入漏洞,该漏洞源于prompt分支选择器中存在命令注入,可能导致能够向Warp中打开的Git仓库发布分支的用户,通过UI使受害者选择特制分支名称,从而在受害者Shell中执行命令。
CVSS Information
N/A
Vulnerability Type
N/A