Description
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
Published: 2026-07-23
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in JetBrains PhpStorm exists in versions prior to 2026.2. An attacker can trigger arbitrary code execution before the user explicitly grants project trust via the project’s tooling interface. This allows a malicious actor to run code with the permissions of the user who opens the project, potentially compromising confidentiality, integrity, or availability of the system. The issue is classified as CWE-829, indicating a security issue related to improper authorization or trust boundary violations.

Affected Systems

JetBrains PhpStorm users running any release before 2026.2 are affected. No specific build numbers are listed beyond the product version threshold, so all earlier releases are considered vulnerable.

Risk and Exploitability

The CVSS score of 8.4 reflects a high severity vulnerability. The EPSS score is less than 1 %, so widespread exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The description does not explicitly state the required attack vector; it is likely local or requires a trusted project, which is inferred from the fact that the flaw occurs before the trust prompt is presented and no remote execution pathway is mentioned. An attacker can supply a malicious project file or manipulate project tooling to trigger code execution before the user grants trust, as stated. The impact remains significant for the user who opens the project.

Generated by OpenCVE AI on August 4, 2026 at 15:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains PhpStorm to version 2026.2 or later.
  • If an upgrade is not immediately possible, avoid opening untrusted project files or disable automatic trust granting in the project tooling settings until a patch is applied.
  • Monitor JetBrains release notes and apply any subsequent security updates promptly.

Generated by OpenCVE AI on August 4, 2026 at 15:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution Before Project Trust in JetBrains PhpStorm

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution Before Project Trust in JetBrains PhpStorm

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains phpstorm
Vendors & Products Jetbrains
Jetbrains phpstorm

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jetbrains Phpstorm
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-24T03:56:25.146Z

Reserved: 2026-07-20T18:20:29.509Z

Link: CVE-2026-64808

cve-icon Vulnrichment

Updated: 2026-07-23T13:30:31.771Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T12:18:36.323

Modified: 2026-07-28T17:08:41.140

Link: CVE-2026-64808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere