
Local PoC for CVE-2026-54686 demonstrating DCS lifecycle hook spoofing in Warp terminal. Simulates spoofed CWD and SSH metadata acceptance in vulnerable models, with fixed model rejection.
This repository contains a safe local Proof of Concept for CVE-2026-54686, based on Warp's public advisory GHSA-9w2v-jhww-vm85.
Before the patched release, Warp accepted certain state-mutating DCS lifecycle hooks from the PTY stream without verifying that those hooks were emitted by Warp's shell integration for the active session. If an attacker could cause a victim to view attacker-controlled terminal output in Warp, selected lifecycle metadata could be spoofed, including current working directory metadata for the active block and SSH session transport metadata.
This PoC does not connect to Warp or to any SSH server, and it does not execute
arbitrary commands. It locally generates and parses Warp-like DCS JSON hooks to
show that a vulnerable model accepts spoofed CWD and SSH metadata, while a fixed
model rejects state-mutating hooks with missing or unregistered session_id
values.
This project is for educational and ethical security testing purposes only. Do not use it against systems or environments where you do not have explicit permission.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)>= v0.2021.04.25.23.05.stable_00v0.2026.05.06.15.42.stable_01Successful exploitation of the scoped CWD issue may cause Warp to treat an attacker-chosen path as the active session's current working directory. This can affect Warp features that seed path, context, or session behavior from the active CWD.
Spoofed SSH lifecycle metadata may also update Warp's stored SSH session transport metadata with attacker-controlled values.
Warp's shell integration sends lifecycle hooks such as Precmd,
CommandFinished, InputBuffer, and SSH to the client using terminal DCS
sequences. Before the fix, some state-mutating hooks did not require proof that
they carried a session_id generated by the Warp client and registered for the
active session.
The patch injects non-zero client-generated session IDs into bootstrap scripts
and rejects state-mutating DCS hooks whose session_id is missing or
unregistered. The SSH wrapper path was also changed so the local SSH hook is
authenticated, a client-generated remote session ID is registered, and that
remote ID is injected into the remote bootstrap.
Python 3 is required:
python3 --version
python3 poc.py
Expected result:
[!] VULNERABLE: spoofed cwd was accepted.
[!] VULNERABLE: spoofed ssh metadata was accepted.
python3 poc.py --mode fixed
Expected result:
[+] FIXED: spoofed cwd was rejected.
[+] FIXED: spoofed ssh metadata was rejected.
python3 poc.py --case cwd
python3 poc.py --case ssh
Use --show-stream to print the generated Warp-like DCS stream using Python
repr(). The script does not print raw terminal control sequences.
Update to v0.2026.05.06.15.42.stable_01 or later. The public advisory states
that there is no complete workaround other than updating.