Executive brief
PhpStorm, a popular development environment for PHP developers, contained a security flaw that could allow malicious code to run on a user's computer. This could happen automatically when opening a project, even before the user has explicitly marked the project as 'trusted.' An attacker could use this to gain full control over a developer's workstation, potentially leading to the theft of source code, credentials, or sensitive company data.
Technical details
A vulnerability in JetBrains PhpStorm versions prior to 2026.2 allowed for arbitrary code execution due to improper handling of untrusted control spheres (CWE-829). The flaw exists in the way the IDE interacts with configured interpreters when a project is first opened. Specifically, the application could execute code through the interpreter before the 'Project Trust' security mechanism had a chance to intervene and block unauthorized actions. An attacker could exploit this by providing a malicious project configuration that triggers code execution upon being loaded by the IDE. This issue has been resolved in version 2026.2.
Affected products
- JetBrains PhpStorm before 2026.2
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory