Junglewise Threat Intelligence

CVE-2026-64809: JetBrains PhpStorm arbitrary code execution via configured interpreter

CVE-2026-64809 · Severity: high · CVSS 8.4 · Published 2026-07-23

Vendors: Jetbrains.

Executive brief

PhpStorm, a popular development environment for PHP developers, contained a security flaw that could allow malicious code to run on a user's computer. This could happen automatically when opening a project, even before the user has explicitly marked the project as 'trusted.' An attacker could use this to gain full control over a developer's workstation, potentially leading to the theft of source code, credentials, or sensitive company data.

Technical details

A vulnerability in JetBrains PhpStorm versions prior to 2026.2 allowed for arbitrary code execution due to improper handling of untrusted control spheres (CWE-829). The flaw exists in the way the IDE interacts with configured interpreters when a project is first opened. Specifically, the application could execute code through the interpreter before the 'Project Trust' security mechanism had a chance to intervene and block unauthorized actions. An attacker could exploit this by providing a malicious project configuration that triggers code execution upon being loaded by the IDE. This issue has been resolved in version 2026.2.

Affected products

  • JetBrains PhpStorm before 2026.2

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats