Impact
JetBrains WebStorm versions prior to 2026.2 contain a flaw that allows arbitrary execution of code via a project‑supplied linter configuration. By crafting a malicious configuration file an attacker can run arbitrary code on the machine running WebStorm, leading to complete compromise of the local environment, including file system access, network resources, and potentially privilege escalation. The underlying weakness is the failure to restrict input capable of executing code, identified as CWE‑829.
Affected Systems
The vulnerability affects JetBrains WebStorm on all releases before 2026.2. No other JetBrains products are listed as impacted. Users of older WebStorm versions should verify their edition and consider upgrading to the latest release.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. However, because the flaw enables arbitrary code execution, the potential impact is significant. The likely attack vector involves an attacker with access to the project workspace or the ability to modify project configuration files, allowing injection of a malicious linter configuration.
OpenCVE Enrichment