Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Warp: OS command injection when opening terminal links from WSL
Vulnerability Description
Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. When Warp is running under WSL and cannot open a URL through wslview, it falls back to a Windows command processor path. A URL controlled through terminal output can reach that fallback when the user opens the link. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Warp 输出处理不当漏洞
Vulnerability Description
Warp是Warp公司开源的一个远程管理软件。 Warp 0.2024.03.12.08.02.stable_01版本至0.2026.05.06.15.42.stable_01版本存在安全漏洞,该漏洞源于WSL URL打开回退功能中存在OS命令注入问题,可能导致通过终端输出控制的URL在用户打开链接时触发回退路径。
CVSS Information
N/A
Vulnerability Type
N/A