JetBrains WebStorm <=2026.1: ATE via package-manager tooling
CVE-2026-64805 Published on July 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
Vulnerability Analysis
CVE-2026-64805 can be exploited with local system access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Inclusion of Functionality from Untrusted Control Sphere
The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Products Associated with CVE-2026-64805
Want to know whenever a new CVE is published for JetBrains Webstorm? stack.watch will email you.
Affected Versions
JetBrains WebStorm:- Before 2026.2 is affected.