
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-64808 is an arbitrary code execution vulnerability in JetBrains PhpStorm that allows code to run before a user grants project trust via project tooling. It affects all versions of PhpStorm prior to 2026.2, and was published on July 23, 2026, by JetBrains s.r.o. The vulnerability carries a CVSS v3.1 base score of 8.4 (High), assigned by JetBrains (GitHub Advisory, JetBrains).
The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning PhpStorm improperly loads or executes functionality from project tooling configuration before the user has had the opportunity to review and grant trust to the project. The attack vector is local, requiring no privileges and no user interaction beyond opening a maliciously crafted project. An attacker could embed malicious tooling configuration within a project (e.g., a shared repository or archive) such that code executes automatically when the project is opened in PhpStorm, bypassing the IDE's project trust safety mechanism (GitHub Advisory, JetBrains).
Successful exploitation results in arbitrary code execution with the privileges of the PhpStorm application process, yielding high impact to confidentiality, integrity, and availability of the affected system. An attacker who tricks a developer into opening a crafted project could exfiltrate source code, credentials, or other sensitive data accessible to the IDE, modify project files, or disrupt the development environment. The scope is limited to the local system running PhpStorm, but the developer workstation context often provides access to sensitive repositories, cloud credentials, and internal network resources (GitHub Advisory, JetBrains).
cmd.exe, powershell.exe, /bin/bash, curl, wget, python) shortly after a project is opened.idea.log in the PhpStorm configuration directory) showing tooling execution events prior to any project trust grant dialog being acknowledged.JetBrains has released a fix in PhpStorm version 2026.2; users should upgrade to this version or later immediately (JetBrains). As an interim workaround, restrict local access to systems running vulnerable PhpStorm versions and exercise caution when opening projects from untrusted or unknown sources. Developers should avoid opening projects received from unverified third parties until the upgrade is applied.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."