Executive brief
JetBrains WebStorm, a popular development environment for JavaScript and web technologies, was vulnerable to a security flaw that allowed malicious code to run automatically when opening a project. This could occur even before a user explicitly chose to 'trust' the project, potentially allowing an attacker to compromise a developer's workstation simply by having them open a malicious codebase. This poses a significant risk to intellectual property and local system security.
Technical details
A vulnerability in JetBrains WebStorm (classified as CWE-829: Inclusion of Functionality from Untrusted Control Sphere) allowed for arbitrary code execution when opening a project. The flaw exists in how the IDE handles project-local linter tooling, which could be triggered automatically before the user grants 'Project Trust.' An attacker could exploit this by placing malicious scripts or binaries within a project's local configuration that the IDE executes upon initialization. This is a local attack vector with high impact on confidentiality, integrity, and availability. The issue is resolved in WebStorm version 2026.2.
Affected products
- JetBrains WebStorm before 2026.2
Timeline
- 2026-07-23: advisory: CVE-2026-64804 published by JetBrains
- 2026-07-23: patched: Fixed in version 2026.2