Arbitrary Code Execution in JetBrains PhpStorm Affects User Trust Setting
CVE-2026-64809
8.4HIGH
What is CVE-2026-64809?
A vulnerability in JetBrains PhpStorm allows arbitrary code execution before project trust is granted via the configured interpreter. This occurs in versions prior to 2026.2, exposing users to potential risks if untrusted code is executed without appropriate safeguards.
Affected Version(s)
PhpStorm 0 < 2026.2