Description
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
Published: 2026-07-23
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains WebStorm before version 2026.2 allowed arbitrary code execution during the opening of a project before project trust was established, by exploiting project‑local package‑manager tooling. This weakness, classified as CWE‑829, let an attacker run code in the context of the IDE, potentially compromising the developer’s machine and any connected systems.

Affected Systems

The flaw affects JetBrains WebStorm users on all supported operating systems running versions earlier than 2026.2. Any IDE instance that executes project‑local package‑manager tooling without the project being explicitly trusted is vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity. The EPSS score of <1% suggests exploits are currently rare, and the vulnerability is not listed in the CISA KEV catalog, implying no documented large‑scale exploitation. Based on the description, the attack requires local or compromised user level access; an attacker would need to trigger the IDE’s package‑manager execution before project trust is granted.

Generated by OpenCVE AI on August 3, 2026 at 21:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains WebStorm to version 2026.2 or later to apply the vendor’s patch.
  • If upgrading is not immediately possible, configure the IDE to reject or pause execution of project‑local package‑manager tooling until the project is explicitly trusted.
  • Limit user permissions within the development environment so that only trusted individuals can add or modify project files that may trigger package‑manager execution.

Generated by OpenCVE AI on August 3, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Untrusted Project-Local Package Manager in WebStorm

Sat, 01 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Untrusted Project-Local Package-Manager Tooling in WebStorm

Mon, 27 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Untrusted Project-Local Package-Manager Tooling in WebStorm

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains webstorm
Vendors & Products Jetbrains
Jetbrains webstorm

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jetbrains Webstorm
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-24T03:56:22.762Z

Reserved: 2026-07-20T18:20:28.785Z

Link: CVE-2026-64805

cve-icon Vulnrichment

Updated: 2026-07-23T13:29:05.975Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T12:18:35.993

Modified: 2026-07-28T17:06:27.437

Link: CVE-2026-64805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:45:03Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere