
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-64806 is an arbitrary code execution vulnerability in JetBrains WebStorm that allows code to run before the user grants project trust via the configured Node.js interpreter. It affects all versions of JetBrains WebStorm prior to 2026.2. The vulnerability was published on July 23, 2026, and is currently undergoing NVD enrichment analysis. It carries a CVSS v3.1 base score of 8.4 (High), assigned by JetBrains (GitHub Advisory, JetBrains).
The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning WebStorm imports or executes functionality — specifically via the configured Node.js interpreter — from a source outside its intended trust boundary before the user has explicitly granted project trust (GitHub Advisory). The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), with low attack complexity (AC:L). In practice, an attacker can craft a malicious project that triggers code execution through the Node.js interpreter during project initialization, bypassing the trust prompt that is intended to protect users from untrusted projects (JetBrains). No public proof-of-concept code has been identified at this time.
Successful exploitation allows a local attacker without any special privileges to execute arbitrary code with the privileges of the WebStorm process. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive files accessible to the WebStorm process, modify project files, and execute arbitrary system commands (GitHub Advisory). The scope is unchanged, meaning the impact is confined to the WebStorm process and its accessible resources, but this still represents a significant risk for developers who open untrusted or shared projects.
package.json scripts, .npmrc, or similar Node.js project files).node, sh, bash, cmd.exe, powershell) before the project trust dialog is displayed.package.json with unusual preinstall, postinstall, or prepare scripts; .npmrc with unexpected registry or script hooks); unexpected new files created in user home or temp directories shortly after opening a project.JetBrains has released a fix in WebStorm version 2026.2; users should upgrade to this version or later as the primary remediation (JetBrains, GitHub Advisory). Until patching is possible, users should exercise caution when opening untrusted, unfamiliar, or externally sourced projects, as malicious code may execute during initialization before the trust prompt appears. Avoid opening projects from untrusted sources or repositories, and review project files (especially package.json scripts) before loading them in WebStorm.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"