# CVE-2026-48721

## Summary

- **CVE ID:** CVE-2026-48721
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- **CWE:** CWE-180, CWE-693
- **Published:** Jun 24, 2026
- **Last Modified:** Jun 25, 2026

## Description

Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The CLI profile is non-interactive and relies on a command denylist as a safety boundary for commands that should require confirmation. Because command strings were checked before canonicalizing leading environment-variable assignments, an attacker who can influence the agent's command output may cause denylisted commands to be treated as non-denylisted. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.

## Affected Products

- warpdotdev — warp (>= 0.2025.10.08.08.12.stable_00, < 0.2026.05.13.09.15.stable_01)

## References

- [CNA](https://github.com/warpdotdev/warp/security/advisories/GHSA-3839-h8jj-ph82)
- [CNA](https://github.com/warpdotdev/warp/commit/0c1e243292c642d9a7748f80813b6fdfc0b31a9e)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 12.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._