Impact
JetBrains WebStorm before version 2026.2 allowed arbitrary code execution during the opening of a project before project trust was established, by exploiting project‑local package‑manager tooling. This weakness, classified as CWE‑829, let an attacker run code in the context of the IDE, potentially compromising the developer’s machine and any connected systems.
Affected Systems
The flaw affects JetBrains WebStorm users on all supported operating systems running versions earlier than 2026.2. Any IDE instance that executes project‑local package‑manager tooling without the project being explicitly trusted is vulnerable.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score of <1% suggests exploits are currently rare, and the vulnerability is not listed in the CISA KEV catalog, implying no documented large‑scale exploitation. Based on the description, the attack requires local or compromised user level access; an attacker would need to trigger the IDE’s package‑manager execution before project trust is granted.
OpenCVE Enrichment