CVE-2026-64806
NixOS 脆弱性の分析と軽減

概要

CVE-2026-64806 is an arbitrary code execution vulnerability in JetBrains WebStorm that allows code to run before the user grants project trust via the configured Node.js interpreter. It affects all versions of JetBrains WebStorm prior to 2026.2. The vulnerability was published on July 23, 2026, and is currently undergoing NVD enrichment analysis. It carries a CVSS v3.1 base score of 8.4 (High), assigned by JetBrains (GitHub Advisory, JetBrains).

技術的な詳細

The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning WebStorm imports or executes functionality — specifically via the configured Node.js interpreter — from a source outside its intended trust boundary before the user has explicitly granted project trust (GitHub Advisory). The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), with low attack complexity (AC:L). In practice, an attacker can craft a malicious project that triggers code execution through the Node.js interpreter during project initialization, bypassing the trust prompt that is intended to protect users from untrusted projects (JetBrains). No public proof-of-concept code has been identified at this time.

影響

Successful exploitation allows a local attacker without any special privileges to execute arbitrary code with the privileges of the WebStorm process. This results in high confidentiality, integrity, and availability impact — an attacker could read sensitive files accessible to the WebStorm process, modify project files, and execute arbitrary system commands (GitHub Advisory). The scope is unchanged, meaning the impact is confined to the WebStorm process and its accessible resources, but this still represents a significant risk for developers who open untrusted or shared projects.

エクスプロイテーションのステップ

  1. Craft a malicious project: An attacker creates or compromises a WebStorm-compatible project directory containing configuration or scripts that are automatically invoked by the configured Node.js interpreter during project initialization (e.g., via package.json scripts, .npmrc, or similar Node.js project files).
  2. Deliver the project to the victim: The attacker distributes the malicious project to a target developer via a code repository, archive file, or shared network location, enticing them to open it in WebStorm.
  3. Trigger execution before trust prompt: When the victim opens the project in a vulnerable version of WebStorm (before 2026.2), the IDE invokes the configured Node.js interpreter against project files before displaying the project trust dialog, causing the attacker's code to execute automatically.
  4. Achieve arbitrary code execution: The malicious Node.js script runs with the privileges of the WebStorm process, enabling the attacker to read sensitive files, exfiltrate data, establish persistence, or execute further system commands (GitHub Advisory, JetBrains).

妥協の兆候

  • Process: Unexpected child processes spawned by the WebStorm process (e.g., node, sh, bash, cmd.exe, powershell) before the project trust dialog is displayed.
  • File System: Presence of suspicious scripts in project directories (e.g., package.json with unusual preinstall, postinstall, or prepare scripts; .npmrc with unexpected registry or script hooks); unexpected new files created in user home or temp directories shortly after opening a project.
  • Network: Outbound network connections initiated by the Node.js process to unknown external hosts immediately after a project is opened in WebStorm.
  • Logs: System or application logs showing Node.js execution events triggered during WebStorm project load, prior to any user interaction with a trust prompt.

軽減策と回避策

JetBrains has released a fix in WebStorm version 2026.2; users should upgrade to this version or later as the primary remediation (JetBrains, GitHub Advisory). Until patching is possible, users should exercise caution when opening untrusted, unfamiliar, or externally sourced projects, as malicious code may execute during initialization before the trust prompt appears. Avoid opening projects from untrusted sources or repositories, and review project files (especially package.json scripts) before loading them in WebStorm.

関連情報


ソースこのレポートは AI を使用して生成されました

関連 NixOS 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-45813HIGH8.8
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45816HIGH7.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45815HIGH7.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45812MEDIUM6.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-46452MEDIUM5.3
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者