CVE-2024-41997
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
14/10/2024
Last modified:
16/10/2024
Description
An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker can create a specially crafted hyperlink using the `warp://action/docker/open_subshell` intent that when clicked by the victim results in command execution on the victim's machine.
Impact
Base Score 3.x
6.60
Severity 3.x
MEDIUM



