PULSE
LIVE50signals / 24h
FEED
ransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Servicesransomthegentlemen reclama a European Design · CA · Otherransomthegentlemen reclama a MK Jewelry · MK · Retail & E-Commerceransomthegentlemen reclama a GUERREIROS seguros · PT · Financial Servicesransomthegentlemen reclama a Tikona Infinet · IN · Technologyransomthegentlemen reclama a TC Printing · AU · Manufacturingransomthegentlemen reclama a Oldelval Oleoductos del Valle · AR · Energy & Utilitiesransomthegentlemen reclama a Decoupe Laser Services · FR · Manufacturingransomthegentlemen reclama a Thialf · NL · Energy & Utilitiesransomthegentlemen reclama a Title Resources · AU · Financial Servicesransomthegentlemen reclama a Clarke Radiology · AU · Healthcareransomthegentlemen reclama a SICSOE · FR · Not Foundransomthegentlemen reclama a Gloria Maris Groupe · FR · Agriculture and Food Productionransomthegentlemen reclama a Compagnie des Caoutchoucs du Pakidie · Manufacturingransomthegentlemen reclama a HBS Group · AU · Professional Services
← All CVEs
CVE WatchJul 23, 2026

CVE-2026-64807

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

CVSS

7.8

High

EPSS

KEV

Exploit Today

0

0-100

Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-829

EPSS · 30d

Not enough EPSS history yet.

Technical description

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-648117.8 HIG
0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration4h
CVE-2026-648098.4 HIG
0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter4h
CVE-2026-648088.4 HIG
0In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling4h
CVE-2026-648068.4 HIG
0In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter4h
CVE-2026-648058.4 HIG
0In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling4h
CVE-2026-648048.4 HIG
0In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling4h