Impact
The vulnerability in JetBrains PhpStorm exists in versions prior to 2026.2. An attacker can trigger arbitrary code execution before the user explicitly grants project trust via the project’s tooling interface. This allows a malicious actor to run code with the permissions of the user who opens the project, potentially compromising confidentiality, integrity, or availability of the system. The issue is classified as CWE-829, indicating a security issue related to improper authorization or trust boundary violations.
Affected Systems
JetBrains PhpStorm users running any release before 2026.2 are affected. No specific build numbers are listed beyond the product version threshold, so all earlier releases are considered vulnerable.
Risk and Exploitability
The CVSS score of 8.4 reflects a high severity vulnerability. The EPSS score is less than 1 %, so widespread exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The description does not explicitly state the required attack vector; it is likely local or requires a trusted project, which is inferred from the fact that the flaw occurs before the trust prompt is presented and no remote execution pathway is mentioned. An attacker can supply a malicious project file or manipulate project tooling to trigger code execution before the user grants trust, as stated. The impact remains significant for the user who opens the project.
OpenCVE Enrichment