CVE-2026-64808
NixOS 脆弱性の分析と軽減

概要

CVE-2026-64808 is an arbitrary code execution vulnerability in JetBrains PhpStorm affecting all versions before 2026.2. The flaw allows code execution to occur before a user grants project trust via project tooling, bypassing a key security boundary in the IDE. It was published on July 23, 2026, with JetBrains as the assigning CNA. The vulnerability carries a CVSS v3.1 base score of 8.4 (High), assigned by JetBrains (GitHub Advisory, JetBrains).

技術的な詳細

The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning PhpStorm imports or executes functionality from an untrusted source — specifically via project tooling — before the user has explicitly granted trust to the project. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), with low attack complexity (AC:L). In practice, an attacker could craft a malicious project with specially configured tooling that triggers code execution as soon as the project is opened in PhpStorm, before the IDE's trust prompt is presented or acted upon. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, JetBrains).

影響

Successful exploitation grants an unauthenticated local attacker arbitrary code execution with the full privileges of the PhpStorm application process, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files accessible to the IDE process, modify project files or system resources, and potentially disrupt the development environment. The scope is limited to the local system running the vulnerable PhpStorm instance, but the compromise of a developer workstation could facilitate further lateral movement into source code repositories, CI/CD pipelines, or connected infrastructure (GitHub Advisory).

エクスプロイテーションのステップ

  1. Craft a malicious project: Create a PhpStorm-compatible project directory containing specially crafted project tooling configuration files (e.g., Composer scripts, PHP CS Fixer configs, or other supported tooling) designed to execute arbitrary code upon project load.
  2. Deliver the project to the target: Distribute the malicious project to a developer who uses a vulnerable version of PhpStorm (any version before 2026.2) via a shared repository, archive file, or social engineering.
  3. Trigger project opening: When the victim opens the project in PhpStorm, the IDE processes the project tooling configuration before presenting the project trust dialog.
  4. Achieve code execution: The malicious tooling configuration causes arbitrary code to execute with the privileges of the PhpStorm process, before the user has the opportunity to grant or deny project trust — bypassing the intended security boundary (GitHub Advisory, JetBrains).

軽減策と回避策

JetBrains has released a fix in PhpStorm version 2026.2; upgrading to this version or later is the recommended remediation. Until an upgrade is possible, users should restrict local access to systems running vulnerable PhpStorm versions and exercise caution when opening projects from untrusted or unknown sources. Avoid opening projects received via email, messaging platforms, or unfamiliar repositories on unpatched installations (JetBrains, GitHub Advisory).

関連情報


ソースこのレポートは AI を使用して生成されました

関連 NixOS 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-45813HIGH8.8
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45816HIGH7.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45815HIGH7.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45812MEDIUM6.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-46452MEDIUM5.3
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者