Description
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
Published: 2026-07-23
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in JetBrains WebStorm is an authorization flaw (CWE‑829) that allows an attacker to execute arbitrary code on a machine that runs the IDE before the user has granted project trust for the configured Node.js interpreter. This lack of proper authorization can lead to full compromise of the system where WebStorm is installed.

Affected Systems

JetBrains WebStorm versions prior to 2026.2 are affected. Users must check that they are running 2026.2 or newer to avoid this risk.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity. The EPSS score is below 1%, suggesting a relatively low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves a local user or an attacker who can run code within the IDE environment, possibly by manipulating the Node.js interpreter configuration before the project is trusted.

Generated by OpenCVE AI on August 3, 2026 at 21:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains WebStorm to version 2026.2 or later.
  • Revoke trust for existing projects and enforce trusted data sources for Node.js interpreters.
  • Disable or limit Node.js interpreter usage in projects that are not verified or vetted.
  • Ensure that authorization checks are enforced for project trust (addressing CWE‑829).

Generated by OpenCVE AI on August 3, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title WebStorm Node.js Interpreter Trust Bypass Enables Arbitrary Code Execution

Sun, 02 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title WebStorm Node.js Interpreter Trust Bypass Enables Arbitrary Code Execution

Sat, 01 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Untrusted Node.js Interpreter Before Project Trust in JetBrains WebStorm

Tue, 28 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Untrusted Node.js Interpreter Before Project Trust in JetBrains WebStorm

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains webstorm
Vendors & Products Jetbrains
Jetbrains webstorm

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jetbrains Webstorm
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-24T03:56:23.574Z

Reserved: 2026-07-20T18:20:29.006Z

Link: CVE-2026-64806

cve-icon Vulnrichment

Updated: 2026-07-23T13:29:31.060Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T12:18:36.103

Modified: 2026-07-28T17:06:35.740

Link: CVE-2026-64806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:45:03Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere