Description
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
Published: 2026-07-23
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains WebStorm versions prior to 2026.2 contain a flaw that allows arbitrary execution of code via a project‑supplied linter configuration. By crafting a malicious configuration file an attacker can run arbitrary code on the machine running WebStorm, leading to complete compromise of the local environment, including file system access, network resources, and potentially privilege escalation. The underlying weakness is the failure to restrict input capable of executing code, identified as CWE‑829.

Affected Systems

The vulnerability affects JetBrains WebStorm on all releases before 2026.2. No other JetBrains products are listed as impacted. Users of older WebStorm versions should verify their edition and consider upgrading to the latest release.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. However, because the flaw enables arbitrary code execution, the potential impact is significant. The likely attack vector involves an attacker with access to the project workspace or the ability to modify project configuration files, allowing injection of a malicious linter configuration.

Generated by OpenCVE AI on August 3, 2026 at 21:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains WebStorm to version 2026.2 or newer.
  • Disable or restrict the use of project‑supplied linter configurations in your projects.
  • Validate and remove any existing malicious linter configuration files from current projects.
  • If upgrading cannot occur immediately, isolate the WebStorm installation and monitor for anomalous script execution.

Generated by OpenCVE AI on August 3, 2026 at 21:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Linter Configuration in JetBrains WebStorm

Mon, 27 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Linter Configuration in JetBrains WebStorm

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains webstorm
Vendors & Products Jetbrains
Jetbrains webstorm

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Jetbrains Webstorm
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-24T03:56:24.355Z

Reserved: 2026-07-20T18:20:29.287Z

Link: CVE-2026-64807

cve-icon Vulnrichment

Updated: 2026-07-23T13:29:54.870Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T12:18:36.217

Modified: 2026-07-28T17:08:25.513

Link: CVE-2026-64807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:45:03Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere