Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepted certain state-mutating terminal lifecycle hooks from the PTY stream without verifying that the hooks were emitted by Warp's shell integration for the active session. An attacker who could cause a victim to view attacker-controlled terminal output in Warp could spoof selected lifecycle metadata, including the current working directory reported for the active block or SSH session transport metadata. This vulnerability is fixed in 0.2026.05.06.15.42.stable_01.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small standalone Python proof-of-concept for CVE-2026-54686 affecting Warp remote SSH helper command handling. Structure is minimal: `README.md` documents the vulnerability, root cause, usage, and remediation; `poc.py` is the executable PoC. The script is not a real remote exploit against Warp or SSH infrastructure; instead, it safely simulates three vulnerable string-construction patterns locally. Main capabilities: (1) builds a vulnerable `cd '<cwd>' && <command>` shell string to demonstrate single-quote breakout and command injection via attacker-controlled remote cwd; (2) builds a vulnerable `cat <history_file>` shell string to demonstrate command injection via an unquoted history file path; and (3) builds a vulnerable `ssh -o ControlPath=<socket_path> example.invalid true` command line to demonstrate SSH option injection when a malicious socket path introduces an extra `-o ProxyCommand=...` argument. For the first two cases, the script executes the generated command locally through `/bin/sh -c`. For the SSH option case, it intentionally avoids invoking real `ssh` and instead tokenizes the command with `shlex.split()` and passes it to a fake parser that only recognizes a very specific `ProxyCommand=touch <marker>` pattern. The PoC supports `--case` (`cwd`, `history`, `ssh-option`, or `all`), `--mode` (`vulnerable` or `fixed`), `--marker-dir`, and `--keep-existing-markers`. In vulnerable mode it expects marker files under `/tmp` (or a user-specified absolute marker directory) to be created; in fixed mode it uses safer quoting/escaping (`shlex.quote` and explicit single-quote escaping) and expects no marker creation. This makes the repository a safe educational exploit simulation rather than a weaponized exploit. It demonstrates exploitability and impact clearly, but payload behavior is limited to local marker-file creation.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.