
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-64809 is an arbitrary code execution vulnerability in JetBrains PhpStorm that allows a local attacker to execute code before the user grants project trust via the configured interpreter. All versions of PhpStorm prior to 2026.2 are affected. The CVE was published on July 23, 2026, and was assigned by JetBrains s.r.o. It carries a CVSS v3.1 base score of 8.4 (High), as assessed by JetBrains (JetBrains Advisory, NVD).
The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning PhpStorm incorporates or executes functionality sourced from an untrusted context — specifically, the configured PHP interpreter — before the IDE's project trust mechanism has been invoked or confirmed by the user. This allows a malicious project (e.g., one cloned from an untrusted repository) to trigger code execution through the interpreter configuration without requiring elevated privileges or user interaction beyond opening the project. The attack vector is local, with low attack complexity and no privileges required (NVD, JetBrains Advisory). No public PoC exploit code has been identified at this time.
Successful exploitation results in high impact to confidentiality, integrity, and availability on the affected system, as indicated by the CVSS scoring. An attacker who can place a malicious project on the victim's machine — for example, via a shared repository or social engineering — could achieve arbitrary code execution in the context of the user running PhpStorm, without any privilege escalation or user interaction beyond opening the project. This could lead to data theft, installation of persistent malware, or further lateral movement within the developer's environment (NVD, JetBrains Advisory).
.idea/ directory settings)..idea/php.xml or other PhpStorm project configuration files pointing to an unusual or external interpreter path; presence of unfamiliar executables referenced as PHP interpreters.JetBrains has released PhpStorm version 2026.2, which resolves this vulnerability. Users should update to PhpStorm 2026.2 or later as the primary remediation (JetBrains Advisory). As a workaround prior to patching, developers should avoid opening projects from untrusted or unknown sources, and should manually review .idea/ configuration files — particularly interpreter settings — before opening any externally sourced project. No additional configuration-based mitigations have been published by JetBrains.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"