CVE-2026-64806: High severity JetBrains WebStorm vulnerability
Published Jul 23, 2026
·Updated
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
Affected Software
2 affected components
JetBrains WebStorm<2026.2
JetBrains WebStorm<2026.2.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains WebStormto a version that resolves this vulnerability.Fixed in 2026.2
Event History
Jul 23, 2026
CVE Published
via MITRE·11:36 AM
Data Sourced
via MITRE·11:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-64806?
CVE-2026-64806 has a high severity rating of 8.4.
2
What does CVE-2026-64806 affect?
CVE-2026-64806 affects JetBrains WebStorm versions prior to 2026.2.
3
What is the risk associated with CVE-2026-64806?
The risk associated with CVE-2026-64806 is rated at 74.
4
How do I fix CVE-2026-64806?
To fix CVE-2026-64806, upgrade JetBrains WebStorm to version 2026.2 or later.
5
What type of vulnerability is CVE-2026-64806?
CVE-2026-64806 is an arbitrary code execution vulnerability.