
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-64807 is an arbitrary code execution vulnerability in JetBrains WebStorm caused by improper handling of project-supplied linter configurations. It affects all WebStorm versions before 2026.2 and was disclosed on July 23, 2026, by JetBrains. The vulnerability carries a CVSS v3.1 base score of 7.8 (High), assigned by JetBrains as the CNA (JetBrains Advisory, NVD).
The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning WebStorm loads and executes linter configuration files supplied by a project without sufficient validation or sandboxing. An attacker can craft a malicious linter configuration file (e.g., an ESLint or Stylelint config) within a project repository; when a victim opens the project in a vulnerable WebStorm version, the IDE automatically processes the configuration and executes attacker-controlled code. Exploitation requires local access to the target machine and user interaction (opening the malicious project), but no privileges are required (JetBrains Advisory, NVD).
Successful exploitation results in arbitrary code execution in the context of the user running WebStorm, with high impact to confidentiality, integrity, and availability. An attacker could read sensitive files, modify project data, install persistent malware, or use the compromised developer workstation as a pivot point for lateral movement into internal networks or CI/CD pipelines. The scope is limited to the affected system (unchanged scope), but developer machines typically have access to source code repositories, credentials, and internal services, amplifying the potential damage (NVD).
.eslintrc.js or eslint.config.js) that executes arbitrary code when loaded by the linter plugin — for example, by requiring a malicious Node.js module or using a plugin field pointing to attacker-controlled code..eslintrc.js, eslint.config.js, .stylelintrc.js, etc.) in project root directories containing require() calls to external or unusual modules; newly created files in user home or temp directories shortly after opening a project.node, sh, bash, powershell, cmd) executing scripts not associated with normal IDE operation; unexpected network connections initiated by Node.js processes launched from within the IDE.idea.log) showing linter plugin loading events for unfamiliar configuration files; OS-level audit logs recording process creation events with WebStorm as the parent process.JetBrains has addressed this vulnerability in WebStorm 2026.2; users should upgrade to this version or later immediately. As a workaround prior to upgrading, developers should avoid opening untrusted or unreviewed projects in WebStorm, and manually inspect linter configuration files for suspicious content before loading a project. Disabling automatic linter integration in IDE settings may also reduce exposure until a patch can be applied (JetBrains Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"