
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-64809 is an arbitrary code execution vulnerability in JetBrains PhpStorm that allows a local unprivileged user to execute arbitrary code before the project trust mechanism is engaged, exploiting the configured interpreter. It affects all versions of JetBrains PhpStorm before 2026.2. The vulnerability was published on July 23, 2026, and assigned by JetBrains s.r.o. It carries a CVSS v3.1 base score of 8.4 (High), as assigned by JetBrains (JetBrains Advisory, NVD).
The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning PhpStorm improperly invokes or loads functionality — specifically the configured PHP interpreter — from an untrusted source before the user has granted trust to the opened project. This allows a malicious project (e.g., one cloned from an untrusted repository) to trigger code execution via the interpreter configuration embedded in the project, bypassing the intended project trust safety gate. The attack vector is local, requires no privileges and no user interaction beyond opening a malicious project, making it exploitable in scenarios where developers open untrusted codebases (JetBrains Advisory, NVD).
Successful exploitation allows a local attacker to execute arbitrary code with the privileges of the PhpStorm process before any project trust validation occurs, resulting in high confidentiality, integrity, and availability impact. An attacker who can cause a developer to open a maliciously crafted project could achieve full control over the developer's workstation environment, potentially accessing source code, credentials, SSH keys, and other sensitive developer assets. This could serve as an initial foothold for lateral movement within a development or CI/CD environment (NVD, JetBrains Advisory).
.idea/ files) that specifies a malicious or attacker-controlled PHP interpreter path or script as the configured interpreter..idea/ project configuration files referencing unusual or non-standard PHP interpreter paths; presence of unknown executables in project directories masquerading as PHP interpreters.idea.log) showing interpreter invocation events prior to project trust being granted; entries referencing unexpected interpreter paths.JetBrains has released a fix in PhpStorm version 2026.2; users should upgrade to this version or later immediately (JetBrains Advisory). As a temporary workaround until patching is possible, restrict local access to systems running vulnerable PhpStorm versions and avoid opening projects from untrusted or unknown sources. Developers should also review and validate any project configuration files (particularly .idea/ directories) before opening projects cloned from external repositories.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."