Description
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
Published: 2026-07-23
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in JetBrains WebStorm versions prior to 2026.2 allows a malicious project to trigger the project‑local linter tooling before the project is granted trust, giving an attacker the ability to execute arbitrary code with the privileges of the user opening the project. The vulnerability is classified as CWE‑829 and can compromise confidentiality, integrity, and availability by running attacker supplied code while the IDE believes the project is trusted.

Affected Systems

JetBrains WebStorm users running any build of the product earlier than 2026.2 are affected. No other vendors or products are listed as vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity flaw. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that a malicious project is opened, the linter tooling is executed before trust is granted, and attacker code runs in the context of the user. No additional prerequisites are specified in the description, so the exploit appears to be locally accessible by anyone who can open a malicious project.

Generated by OpenCVE AI on August 4, 2026 at 15:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains WebStorm to version 2026.2 or later to receive the vendor patch.
  • If an upgrade cannot be performed immediately, disable or restrict the use of project‑local linter tooling until the update is applied.
  • Monitor system logs for unexpected linter activity and review any newly opened project configurations.

Generated by OpenCVE AI on August 4, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Code Execution via Untrusted Project-Local Linter in JetBrains WebStorm

Sun, 02 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Code Execution via Untrusted Project-Local Linter in JetBrains WebStorm

Sat, 01 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title WebStorm Linter Exploit Allowing Arbitrary Code Execution

Mon, 27 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title WebStorm Linter Exploit Allowing Arbitrary Code Execution

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains webstorm
Vendors & Products Jetbrains
Jetbrains webstorm

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jetbrains Webstorm
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-24T03:56:21.618Z

Reserved: 2026-07-20T18:20:28.432Z

Link: CVE-2026-64804

cve-icon Vulnrichment

Updated: 2026-07-23T13:28:03.880Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T12:18:35.880

Modified: 2026-07-28T17:06:18.890

Link: CVE-2026-64804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere