8.6 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
Warp: Env-var prefixes can lead to denylisted command autoexecution
Warp is an agentic development environment. From 0.2025.10.08.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution permission-check bypass in the default unsandboxed CLI agent profile. The CLI profile is non-interactive and relies on a command denylist as a safety boundary for commands that should require confirmation. Because command strings were checked before canonicalizing leading environment-variable assignments, an attacker who can influence the agent's command output may cause denylisted commands to be treated as non-denylisted. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
References
Affected products
- ==>= 0.2025.10.08.08.12.stable_00, < 0.2026.05.13.09.15.stable_01
Matching in nixpkgs
pkgs.warp
Fast and secure file transfer
pkgs.warpd
Modal keyboard driven interface for mouse manipulation
pkgs.ts-warp
Transparent proxy server and traffic wrapper
pkgs.warpgate
Smart SSH, HTTPS, MySQL and Postgres bastion that requires no additional client-side software
pkgs.warp-plus
None
pkgs.minio-warp
S3 benchmarking tool
pkgs.warpinator
Share files across the LAN
pkgs.git-warp-time
Utility to reset filesystem timestamps based on Git history
pkgs.warp-terminal
Rust-based terminal
-
nixos-unstable -
- nixos-unstable-small 0.2026.06.03.09.49.stable_01
-
nixos-26.05 -
- nixos-26.05-small 0.2026.04.15.08.45.stable_04
pkgs.cloudflare-warp
Replaces the connection between your device and the Internet with a modern, optimized, protocol
-
nixos-unstable -
- nixos-unstable-small 2026.3.846.0
-
nixos-26.05 -
- nixos-26.05-small 2026.3.846.0
pkgs.haskellPackages.warp
A fast, light-weight web server for WAI applications
pkgs.haskellPackages.warp-tls
HTTP over TLS support for Warp via the TLS package
pkgs.gnomeExtensions.warpgnome
Toggle Cloudflare WARP in quick settings.
pkgs.gnomeExtensions.mouse-warp
Moves the mouse cursor to the center of the focused window on focus change.
pkgs.gnomeExtensions.warp-toggle
Toggle Cloudflare WARP connection from Quick Settings menu
pkgs.python312Packages.warp-lang
None
pkgs.python313Packages.warp-lang
Python framework for high performance GPU simulation and graphics
pkgs.python314Packages.warp-lang
Python framework for high performance GPU simulation and graphics
pkgs.haskellPackages.jsaddle-warp
Interface for JavaScript that works with GHCJS and GHC
pkgs.haskellPackages.warp-systemd
Socket activation and other systemd integration for the Warp web server (WAI)
pkgs.haskellPackages.core-webserver-warp
Interoperability with Wai/Warp
pkgs.gnomeExtensions.cloudflare-warp-toggle
Toggle cloudflare warp in quick settings.
pkgs.gnomeExtensions.cloudflare-warp-indicator
System tray indicator and controls for Cloudflare WARP VPN. Shows connection status, info panel, and connect/disconnect toggle via warp-cli.
pkgs.haskellPackages.essence-of-live-coding-warp
General purpose live coding framework