CVE-2026-64809
NixOS 脆弱性の分析と軽減

概要

CVE-2026-64809 is an arbitrary code execution vulnerability in JetBrains PhpStorm that allows a local attacker to execute code before the user grants project trust via the configured interpreter. All versions of PhpStorm prior to 2026.2 are affected. The CVE was published on July 23, 2026, and was assigned by JetBrains s.r.o. It carries a CVSS v3.1 base score of 8.4 (High), as assessed by JetBrains (JetBrains Advisory, NVD).

技術的な詳細

The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning PhpStorm incorporates or executes functionality sourced from an untrusted context — specifically, the configured PHP interpreter — before the IDE's project trust mechanism has been invoked or confirmed by the user. This allows a malicious project (e.g., one cloned from an untrusted repository) to trigger code execution through the interpreter configuration without requiring elevated privileges or user interaction beyond opening the project. The attack vector is local, with low attack complexity and no privileges required (NVD, JetBrains Advisory). No public PoC exploit code has been identified at this time.

影響

Successful exploitation results in high impact to confidentiality, integrity, and availability on the affected system, as indicated by the CVSS scoring. An attacker who can place a malicious project on the victim's machine — for example, via a shared repository or social engineering — could achieve arbitrary code execution in the context of the user running PhpStorm, without any privilege escalation or user interaction beyond opening the project. This could lead to data theft, installation of persistent malware, or further lateral movement within the developer's environment (NVD, JetBrains Advisory).

エクスプロイテーションのステップ

  1. Prepare malicious project: An attacker crafts a PhpStorm project that includes a malicious or attacker-controlled PHP interpreter path in the project's configuration files (e.g., .idea/ directory settings).
  2. Deliver the project: The attacker distributes the malicious project to the target developer, for example via a public or private Git repository, a shared archive, or social engineering.
  3. Victim opens the project: The target developer opens the project in a vulnerable version of PhpStorm (before 2026.2). At this stage, the IDE has not yet prompted for or received project trust confirmation.
  4. Interpreter executes before trust check: PhpStorm invokes the configured (attacker-controlled) interpreter prior to completing the project trust validation flow, triggering execution of arbitrary code in the context of the developer's user account.
  5. Achieve objective: The attacker's payload executes with the developer's privileges, enabling data exfiltration, persistence, or further compromise of the development environment (NVD, JetBrains Advisory).

妥協の兆候

  • File System: Unexpected or modified .idea/php.xml or other PhpStorm project configuration files pointing to an unusual or external interpreter path; presence of unfamiliar executables referenced as PHP interpreters.
  • Process: Unusual child processes spawned by the PhpStorm process (e.g., unexpected scripts, shells, or binaries) shortly after a project is opened, particularly before any trust dialog is displayed.
  • Logs: PhpStorm logs (located in the IDE's log directory) showing interpreter invocation events prior to project trust being granted; unexpected process execution entries in OS audit logs tied to the PhpStorm process.
  • Network: Outbound network connections initiated by processes spawned from PhpStorm to unknown external hosts, potentially indicating a reverse shell or data exfiltration payload.

軽減策と回避策

JetBrains has released PhpStorm version 2026.2, which resolves this vulnerability. Users should update to PhpStorm 2026.2 or later as the primary remediation (JetBrains Advisory). As a workaround prior to patching, developers should avoid opening projects from untrusted or unknown sources, and should manually review .idea/ configuration files — particularly interpreter settings — before opening any externally sourced project. No additional configuration-based mitigations have been published by JetBrains.

関連情報


ソースこのレポートは AI を使用して生成されました

関連 NixOS 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-45813HIGH8.8
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45816HIGH7.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45815HIGH7.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-45812MEDIUM6.5
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026
CVE-2026-46452MEDIUM5.3
  • NixOS logoNixOS
  • nimble
いいえはいJul 24, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者