Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Warp: Env-var prefixes can lead to denylisted command autoexecution
Vulnerability Description
Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The CLI profile is non-interactive and relies on a command denylist as a safety boundary for commands that should require confirmation. Because command strings were checked before canonicalizing leading environment-variable assignments, an attacker who can influence the agent's command output may cause denylisted commands to be treated as non-denylisted. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
不正确的行为次序:规范化之前验证
Vulnerability Title
Warp 处理逻辑错误漏洞
Vulnerability Description
Warp是Warp公司开源的一个远程管理软件。 Warp 0.2025.10.08.08.12.stable_00版本至0.2026.05.06.15.42.stable_01之前版本存在处理逻辑错误漏洞,该漏洞源于在规范前导环境变量赋值之前检查命令字符串,可能导致能够影响代理命令输出的攻击者将列入黑名单的命令视为未列入黑名单,从而绕过默认非沙箱化CLI代理配置文件中的命令执行权限检查。
CVSS Information
N/A
Vulnerability Type
N/A