8.0 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
23 packages
- warp
- warpd
- ts-warp
- warpgate
- warp-plus
- minio-warp
- warpinator
- git-warp-time
- cloudflare-warp
- haskellPackages.warp
- haskellPackages.warp-tls
- gnomeExtensions.warpgnome
- gnomeExtensions.mouse-warp
- gnomeExtensions.warp-toggle
- python312Packages.warp-lang
- python313Packages.warp-lang
- python314Packages.warp-lang
- haskellPackages.jsaddle-warp
- haskellPackages.warp-systemd
- haskellPackages.core-webserver-warp
- gnomeExtensions.cloudflare-warp-toggle
- gnomeExtensions.cloudflare-warp-indicator
- haskellPackages.essence-of-live-coding-warp
- @LeSuisse accepted
- @LeSuisse published on GitHub
Warp branch selector command injection via Git branch names
Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publish a branch to a Git repository opened in Warp can cause a crafted branch name to be interpreted by the victim's shell if the victim selects that branch from the UI. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
References
Affected products
- ==>= 0.2025.08.06.08.12.stable_00, < 0.2026.05.13.09.15.stable_01
Matching in nixpkgs
pkgs.warp-terminal
Rust-based terminal
-
nixos-unstable 0.2026.06.03.09.49.stable_01
- nixpkgs-unstable 0.2026.06.03.09.49.stable_01
- nixos-unstable-small 0.2026.06.03.09.49.stable_01
-
nixos-26.05 0.2026.04.15.08.45.stable_04
- nixos-26.05-small 0.2026.04.15.08.45.stable_04
- nixpkgs-26.05-darwin 0.2026.04.15.08.45.stable_04
Ignored packages (23)
pkgs.warp
Fast and secure file transfer
pkgs.warpd
Modal keyboard driven interface for mouse manipulation
pkgs.ts-warp
Transparent proxy server and traffic wrapper
pkgs.warpgate
Smart SSH, HTTPS, MySQL and Postgres bastion that requires no additional client-side software
pkgs.warp-plus
None
pkgs.minio-warp
S3 benchmarking tool
pkgs.warpinator
Share files across the LAN
pkgs.git-warp-time
Utility to reset filesystem timestamps based on Git history
pkgs.cloudflare-warp
Replaces the connection between your device and the Internet with a modern, optimized, protocol
-
nixos-unstable 2026.3.846.0
- nixpkgs-unstable 2026.3.846.0
- nixos-unstable-small 2026.3.846.0
-
nixos-26.05 2026.3.846.0
- nixos-26.05-small 2026.3.846.0
- nixpkgs-26.05-darwin 2026.3.846.0
pkgs.haskellPackages.warp
A fast, light-weight web server for WAI applications
pkgs.haskellPackages.warp-tls
HTTP over TLS support for Warp via the TLS package
pkgs.gnomeExtensions.warpgnome
Toggle Cloudflare WARP in quick settings.
pkgs.gnomeExtensions.mouse-warp
Moves the mouse cursor to the center of the focused window on focus change.
pkgs.gnomeExtensions.warp-toggle
Toggle Cloudflare WARP connection from Quick Settings menu
pkgs.python312Packages.warp-lang
None
pkgs.python313Packages.warp-lang
Python framework for high performance GPU simulation and graphics
pkgs.python314Packages.warp-lang
Python framework for high performance GPU simulation and graphics
pkgs.haskellPackages.jsaddle-warp
Interface for JavaScript that works with GHCJS and GHC
pkgs.haskellPackages.warp-systemd
Socket activation and other systemd integration for the Warp web server (WAI)
pkgs.haskellPackages.core-webserver-warp
Interoperability with Wai/Warp
pkgs.gnomeExtensions.cloudflare-warp-toggle
Toggle cloudflare warp in quick settings.
pkgs.gnomeExtensions.cloudflare-warp-indicator
System tray indicator and controls for Cloudflare WARP VPN. Shows connection status, info panel, and connect/disconnect toggle via warp-cli.
Package maintainers
-
@i-am-logger Ido Samuelson <ido.samuelson@gmail.com>
-
@FlameFlag FlameFlag <github@flameflag.dev>
-
@johnrtitor Masum Reza <masumrezarock100@gmail.com>