CVE-2026-64809
Published Jul 23, 2026In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
6 CVEs tagged to jetbrains / phpstorm — 2 Critical, 2 High, 1 Medium, 1 Low, 0 Unrated.
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3;…
In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2…
In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.