Junglewise Threat Intelligence

CVE-2026-64804: JetBrains WebStorm arbitrary code execution via project-local linters

CVE-2026-64804 · Severity: high · CVSS 8.4 · Published 2026-07-23

Technologies: Jetbrains WebStorm. Vendors: Jetbrains.

Executive brief

JetBrains WebStorm, a popular development environment for JavaScript and web technologies, was vulnerable to a security flaw that allowed malicious code to run automatically when opening a project. This could occur even before a user explicitly chose to 'trust' the project, potentially allowing an attacker to compromise a developer's workstation simply by having them open a malicious codebase. This poses a significant risk to intellectual property and local system security.

Technical details

A vulnerability in JetBrains WebStorm (classified as CWE-829: Inclusion of Functionality from Untrusted Control Sphere) allowed for arbitrary code execution when opening a project. The flaw exists in how the IDE handles project-local linter tooling, which could be triggered automatically before the user grants 'Project Trust.' An attacker could exploit this by placing malicious scripts or binaries within a project's local configuration that the IDE executes upon initialization. This is a local attack vector with high impact on confidentiality, integrity, and availability. The issue is resolved in WebStorm version 2026.2.

Affected products

  • JetBrains WebStorm before 2026.2

Timeline

  • 2026-07-23: advisory: CVE-2026-64804 published by JetBrains
  • 2026-07-23: patched: Fixed in version 2026.2

References

Related threats