CVE-2026-48732
Last modified
CVE-2026-48732 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH background command path. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH background command path. Warp used the remote working directory reported by the session when building helper commands for SSH-backed metadata collection. A remote host, repository, or directory name controlled by an attacker could cause that helper command to execute additional shell syntax on the remote host as the victim's authenticated SSH account. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-48732?
How severe is CVE-2026-48732?
How do I fix CVE-2026-48732?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48723The browserstack-cypress-cli is BrowserStack's CLI which all…7.8
- CVE-2026-48724ImageMagick is free and open-source software used for editin…5.5
- CVE-2026-48725Warp is an agentic development environment. From 0.2021.04.2…8.1
- CVE-2026-48726A bug in Apache Airflow's auth manager logout handling left …6.5
- CVE-2026-4873A vulnerability exists where a connection requiring TLS inco…5.9
- CVE-2026-48731Warp is an agentic development environment. From 0.2024.02.2…7.8
- CVE-2026-48733ImageMagick is free and open-source software used for editin…4.7
- CVE-2026-48734ImageMagick is free and open-source software used for editin…5.5
- CVE-2026-48735pypdf is a free and open-source pure-python PDF library. Pri…5.5
- CVE-2026-48736Symfony is a PHP framework for web and console applications …8.6
- CVE-2026-4874A flaw was found in Keycloak. An authenticated attacker can …3.1
- CVE-2026-48743Envoy is an open source edge and service proxy designed for …7.5
Are you affected by CVE-2026-48732?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
