Arbitrary Code Execution in JetBrains WebStorm Affected by Linter Configuration
CVE-2026-64807
7.8HIGH
What is CVE-2026-64807?
A vulnerability in JetBrains WebStorm prior to version 2026.2 allows arbitrary code execution through a maliciously crafted linter configuration supplied within a project. This flaw can enable an attacker to execute code with the privileges of the user running the IDE, thereby posing a significant security risk. Users of affected versions are urged to review their linter configurations and upgrade to the latest version to mitigate potential threats.
Affected Version(s)
WebStorm 0 < 2026.2