CVE-2026-64805

JetBrains · WebStorm

A vulnerability in JetBrains WebStorm versions prior to 2026.2 allows for the inclusion of untrusted functionality, which could potentially lead to unauthorized system actions.

Executive summary

JetBrains WebStorm versions before 2026.2 are affected by a security flaw involving the inclusion of untrusted components, presenting a high risk to the development environment.

Vulnerability

This issue is identified as CWE-829, involving the inclusion of functionality from an untrusted control sphere. The vulnerability allows for exploitation by an attacker without requiring specific authentication, based on the provided CVSS vector.

Business impact

Exploitation of this vulnerability could lead to significant security breaches within the development workstation, potentially resulting in the loss of proprietary source code or credentials. The CVSS score of 8.4 underscores the high severity and the need for immediate remediation to protect organizational assets.

Remediation

Immediate Action: Upgrade all installations of JetBrains WebStorm to version 2026.2 or the latest available release.

Proactive Monitoring: Audit logs for unusual activity or unauthorized component loading within the WebStorm environment.

Compensating Controls: Apply strict network and host-based access controls to limit the potential impact if a developer workstation is compromised.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Security teams should enforce the update to version 2026.2 across all developer machines immediately. Addressing this vulnerability is critical to maintaining a secure development environment and preventing potential downstream impacts to production code.