Impact
The vulnerability in JetBrains WebStorm is an authorization flaw (CWE‑829) that allows an attacker to execute arbitrary code on a machine that runs the IDE before the user has granted project trust for the configured Node.js interpreter. This lack of proper authorization can lead to full compromise of the system where WebStorm is installed.
Affected Systems
JetBrains WebStorm versions prior to 2026.2 are affected. Users must check that they are running 2026.2 or newer to avoid this risk.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity. The EPSS score is below 1%, suggesting a relatively low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves a local user or an attacker who can run code within the IDE environment, possibly by manipulating the Node.js interpreter configuration before the project is trusted.
OpenCVE Enrichment