Impact
A flaw in JetBrains WebStorm versions prior to 2026.2 allows a malicious project to trigger the project‑local linter tooling before the project is granted trust, giving an attacker the ability to execute arbitrary code with the privileges of the user opening the project. The vulnerability is classified as CWE‑829 and can compromise confidentiality, integrity, and availability by running attacker supplied code while the IDE believes the project is trusted.
Affected Systems
JetBrains WebStorm users running any build of the product earlier than 2026.2 are affected. No other vendors or products are listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity flaw. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that a malicious project is opened, the linter tooling is executed before trust is granted, and attacker code runs in the context of the user. No additional prerequisites are specified in the description, so the exploit appears to be locally accessible by anyone who can open a malicious project.
OpenCVE Enrichment