CVEFinder.io

CVE-2026-64809

âš ī¸ high
🔍 Scan for this CVE
Summary

In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter

CVSS Score
8.4
High
EPSS Score
0.1
Exploit Probability
Published Date
2026-07-23
First Seen: 2026-07-31
📊 Relative Risk Intelligence

This CVE is High Risk - more severe than 80.2% of all 340,405 vulnerabilities in our database.

#67,540
Top 25% most severe
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Jul 23, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-07-28
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 1

🔗 References 1

🔗 Related CVEs 5

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-64808 âš ī¸ high 8.4 0.1 In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tool... 2026-07-23
CVE-2024-37051 ⛔ critical 9.3 6.3 GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ... 2024-06-10
CVE-2022-48435 â„šī¸ low 3.3 0.0 In JetBrains PhpStorm before 2023.1 source code could be logged in the local idea.log file 2023-04-04
CVE-2021-45977 ⛔ critical 9.8 0.0 JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, ... 2022-02-25
CVE-2021-25764 đŸ”ļ medium 5.3 0.0 In JetBrains PhpStorm before 2020.3, source code could be added to debug logs. 2021-03-18
These CVEs affect the same products