CVE-2026-64807
NixOS 脆弱性の分析と軽減

概要

CVE-2026-64807 is an arbitrary code execution vulnerability in JetBrains WebStorm caused by improper handling of project-supplied linter configurations. It affects all WebStorm versions before 2026.2 and was disclosed on July 23, 2026, by JetBrains. The vulnerability carries a CVSS v3.1 base score of 7.8 (High), assigned by JetBrains as the CNA (JetBrains Advisory, NVD).

技術的な詳細

The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning WebStorm loads and executes linter configuration files supplied by a project without sufficient validation or sandboxing. An attacker can craft a malicious linter configuration file (e.g., an ESLint or Stylelint config) within a project repository; when a victim opens the project in a vulnerable WebStorm version, the IDE automatically processes the configuration and executes attacker-controlled code. Exploitation requires local access to the target machine and user interaction (opening the malicious project), but no privileges are required (JetBrains Advisory, NVD).

影響

Successful exploitation results in arbitrary code execution in the context of the user running WebStorm, with high impact to confidentiality, integrity, and availability. An attacker could read sensitive files, modify project data, install persistent malware, or use the compromised developer workstation as a pivot point for lateral movement into internal networks or CI/CD pipelines. The scope is limited to the affected system (unchanged scope), but developer machines typically have access to source code repositories, credentials, and internal services, amplifying the potential damage (NVD).

エクスプロイテーションのステップ

  1. Craft malicious project: Create or fork a legitimate-looking code repository and embed a malicious linter configuration file (e.g., .eslintrc.js or eslint.config.js) that executes arbitrary code when loaded by the linter plugin — for example, by requiring a malicious Node.js module or using a plugin field pointing to attacker-controlled code.
  2. Distribute the project: Share the malicious repository via a public platform (GitHub, GitLab), a phishing email, or a supply chain compromise targeting a developer's dependencies.
  3. Victim opens project: The target developer opens the project in JetBrains WebStorm (any version before 2026.2). WebStorm automatically detects and loads the linter configuration as part of its IDE integration.
  4. Code execution: The malicious linter configuration triggers execution of attacker-controlled code in the context of the developer's user account, enabling payload delivery such as a reverse shell, credential harvesting, or persistence mechanisms (JetBrains Advisory, NVD).

妥協の兆候

  • File System: Unexpected or unfamiliar linter configuration files (.eslintrc.js, eslint.config.js, .stylelintrc.js, etc.) in project root directories containing require() calls to external or unusual modules; newly created files in user home or temp directories shortly after opening a project.
  • Process: Unusual child processes spawned by the WebStorm JVM process (e.g., node, sh, bash, powershell, cmd) executing scripts not associated with normal IDE operation; unexpected network connections initiated by Node.js processes launched from within the IDE.
  • Network: Outbound connections to unknown external IPs or domains from developer workstations, particularly from Node.js processes, shortly after opening a new project.
  • Logs: IDE logs (idea.log) showing linter plugin loading events for unfamiliar configuration files; OS-level audit logs recording process creation events with WebStorm as the parent process.

軽減策と回避策

JetBrains has addressed this vulnerability in WebStorm 2026.2; users should upgrade to this version or later immediately. As a workaround prior to upgrading, developers should avoid opening untrusted or unreviewed projects in WebStorm, and manually inspect linter configuration files for suspicious content before loading a project. Disabling automatic linter integration in IDE settings may also reduce exposure until a patch can be applied (JetBrains Advisory).

関連情報


ソースこのレポートは AI を使用して生成されました

関連 NixOS 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-45813HIGH8.8
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45816HIGH7.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45815HIGH7.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45812MEDIUM6.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-46452MEDIUM5.3
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者