cve/2024/CVE-2024-41997.md
2025-09-29 21:09:30 +02:00

923 B

CVE-2024-41997

Description

An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker can create a specially crafted hyperlink using the warp://action/docker/open_subshell intent that when clicked by the victim results in command execution on the victim's machine.

POC

Reference

No PoCs from references.

Github