CVE-2026-64804
JetBrains · WebStorm
A vulnerability in JetBrains WebStorm versions prior to 2026.2 involves the inclusion of untrusted functionality or components, which could lead to unauthorized code execution.
Executive summary
JetBrains WebStorm versions before 2026.2 contain a vulnerability related to the inclusion of untrusted components, posing a high risk of unauthorized access or code execution.
Vulnerability
This vulnerability is classified as CWE-829, which involves the inclusion of functionality from an untrusted control sphere. It requires local access but does not require specific user privileges to exploit, according to the CVSS vector PR:N.
Business impact
The ability to include untrusted components can lead to arbitrary code execution within the developer environment. With a CVSS score of 8.4, this represents a severe risk to internal development environments, potentially allowing attackers to compromise intellectual property or pivot into secure corporate networks.
Remediation
Immediate Action: Update JetBrains WebStorm to version 2026.2 or later to address the security defect.
Proactive Monitoring: Monitor developer workstations for unexpected process execution or modifications to project configuration files.
Compensating Controls: Use endpoint security solutions to restrict unauthorized execution of scripts or binaries within the development environment.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should ensure that all development teams update their instances of WebStorm to the latest version immediately. This will mitigate the risk of malicious code injection and maintain the integrity of the development lifecycle.