CVE-2026-64809
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-64809 is an arbitrary code execution vulnerability in JetBrains PhpStorm that allows a local unprivileged user to execute arbitrary code before the project trust mechanism is engaged, exploiting the configured interpreter. It affects all versions of JetBrains PhpStorm before 2026.2. The vulnerability was published on July 23, 2026, and assigned by JetBrains s.r.o. It carries a CVSS v3.1 base score of 8.4 (High), as assigned by JetBrains (JetBrains Advisory, NVD).

Technical details

The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning PhpStorm improperly invokes or loads functionality — specifically the configured PHP interpreter — from an untrusted source before the user has granted trust to the opened project. This allows a malicious project (e.g., one cloned from an untrusted repository) to trigger code execution via the interpreter configuration embedded in the project, bypassing the intended project trust safety gate. The attack vector is local, requires no privileges and no user interaction beyond opening a malicious project, making it exploitable in scenarios where developers open untrusted codebases (JetBrains Advisory, NVD).

Impact

Successful exploitation allows a local attacker to execute arbitrary code with the privileges of the PhpStorm process before any project trust validation occurs, resulting in high confidentiality, integrity, and availability impact. An attacker who can cause a developer to open a maliciously crafted project could achieve full control over the developer's workstation environment, potentially accessing source code, credentials, SSH keys, and other sensitive developer assets. This could serve as an initial foothold for lateral movement within a development or CI/CD environment (NVD, JetBrains Advisory).

Exploitation steps

  1. Craft a malicious project: Create a PhpStorm project directory containing a crafted project configuration (e.g., .idea/ files) that specifies a malicious or attacker-controlled PHP interpreter path or script as the configured interpreter.
  2. Deliver the project to the target: Distribute the malicious project via a public repository (e.g., GitHub), phishing, or social engineering to induce a developer running a vulnerable version of PhpStorm (before 2026.2) to open it.
  3. Trigger automatic interpreter invocation: When the victim opens the project in PhpStorm, the IDE automatically invokes the configured interpreter as part of its initialization or indexing process — before the project trust dialog is presented or confirmed.
  4. Achieve code execution: The malicious interpreter binary or script executes arbitrary code with the privileges of the PhpStorm process on the developer's machine, enabling data exfiltration, persistence, or further lateral movement (NVD, JetBrains Advisory).

Indicators of compromise

  • File System: Unexpected or modified .idea/ project configuration files referencing unusual or non-standard PHP interpreter paths; presence of unknown executables in project directories masquerading as PHP interpreters.
  • Process: Unusual child processes spawned by the PhpStorm JVM process (e.g., unexpected scripts, shells, or binaries) before any user interaction with the project trust dialog.
  • Logs: PhpStorm log files (idea.log) showing interpreter invocation events prior to project trust being granted; entries referencing unexpected interpreter paths.
  • Network: Unexpected outbound network connections originating from the PhpStorm process or a child process shortly after opening a new project.

Mitigation and workarounds

JetBrains has released a fix in PhpStorm version 2026.2; users should upgrade to this version or later immediately (JetBrains Advisory). As a temporary workaround until patching is possible, restrict local access to systems running vulnerable PhpStorm versions and avoid opening projects from untrusted or unknown sources. Developers should also review and validate any project configuration files (particularly .idea/ directories) before opening projects cloned from external repositories.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-66033HIGH8.7
  • NixOS logoNixOS
  • seal-libssh2
NoYesJul 24, 2026
CVE-2026-66035HIGH7.7
  • NixOS logoNixOS
  • libssh2
NoYesJul 24, 2026
CVE-2026-66034HIGH7.7
  • NixOS logoNixOS
  • rust-cargo-c
NoYesJul 24, 2026
CVE-2026-45816HIGH7.5
  • NixOS logoNixOS
  • nimble
NoYesJul 24, 2026
CVE-2026-46452MEDIUM5.3
  • NixOS logoNixOS
  • nimble
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management