Skip to main content

Vendor/product archive

jetbrains / webstorm CVEs

Beta · best-effort

9 CVEs tagged to jetbrains / webstorm3 Critical, 5 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-64807

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64806

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64805

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64804

Published Jul 23, 2026

In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-52555

Published Nov 15, 2024

In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37051

Published Jun 10, 2024

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3;…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2021-31897

Published May 11, 2021

In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1