Jetbrains
Jetbrains Webstorm: vulnerabilidades y CVE
Jetbrains Webstorm tiene 9 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses4
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-64807 | Alta (7.8) | 0.18% | — | 23 jul 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration |
| CVE-2026-64806 | Alta (8.4) | 0.19% | — | 23 jul 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter |
| CVE-2026-64805 | Alta (8.4) | 0.19% | — | 23 jul 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling |
| CVE-2026-64804 | Alta (8.4) | 0.19% | — | 23 jul 2026 | In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling |
| CVE-2024-52555 | Alta (7.8) | 0.11% | — | 15 nov 2024 | In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script |
| CVE-2024-37051 | Alta (7.5) | 3.8% | — | 10 jun 2024 | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4,… |
| CVE-2021-45977 | Crítica (9.8) | 1.1% | — | 25 feb 2022 | JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC,… |
| CVE-2021-31898 | Alta (7.5) | 0.63% | — | 11 may 2021 | In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS. |
| CVE-2021-31897 | Crítica (9.8) | 1.5% | — | 11 may 2021 | In JetBrains WebStorm before 2021.1, code execution without user confirmation was possible for untrusted projects. |