JetBrains Vulnerabilities and Affected Products
Vulnerabilities associated with IntelliJ IDEA.
Products
Clear product- TeamCity183 vulnerabilities
- YouTrack62 vulnerabilities
- IntelliJ IDEA49 vulnerabilities
- Hub16 vulnerabilities
- Ktor10 vulnerabilities
- GoLand6 vulnerabilities
- Rider6 vulnerabilities
- Toolbox App6 vulnerabilities
- WebStorm6 vulnerabilities
- PyCharm5 vulnerabilities
- PhpStorm4 vulnerabilities
- Junie3 vulnerabilities
- ReSharper2 vulnerabilities
- RubyMine2 vulnerabilities
- Aqua1 vulnerability
- CLion1 vulnerability
- DataGrip1 vulnerability
- Datalore1 vulnerability
- DataSpell1 vulnerability
- dotTrace1 vulnerability
- ETW Host Service1 vulnerability
- IDE Services1 vulnerability
- intellij_idea1 vulnerability
- JetBrains Gateway1 vulnerability
- Kotlin1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-64815HIGH | Generated title:JetBrains IntelliJ IDEA UI Designer Form File Code InjectionIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files CWE-94Jul 23, 2026 | CVSS8.1v3.1 | EPSS0.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64814HIGH | Generated title:JetBrains IntelliJ IDEA Remote Development Unauthorized File AccessIn JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session CWE-862Jul 23, 2026 | CVSS8.6v3.1 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64813CRITICAL | Generated title:JetBrains IntelliJ IDEA Remote Development Session Unauthorized Settings ModificationIn JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session CWE-602Jul 23, 2026 | CVSS10.0v3.1 | EPSS0.393% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64812CRITICAL | Generated title:JetBrains IntelliJ IDEA Remote Development Session Unauthorized Input InjectionIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session CWE-306Jul 23, 2026 | CVSS10.0v3.1 | EPSS0.363% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64811HIGH | Generated title:JetBrains IntelliJ IDEA Development Container Configuration Arbitrary Code ExecutionIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration CWE-829Jul 23, 2026 | CVSS7.8v3.1 | EPSS0.126% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-64810MEDIUM | Generated title:JetBrains IntelliJ IDEA HTML Injection in IDE NotificationIn JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking CWE-79Jul 23, 2026 | CVSS4.3v3.1 | EPSS0.149% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-59792CRITICAL | Generated title:JetBrains IntelliJ IDEA Path Traversal Code Execution in Project Workspace ID HandlingIn JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible CWE-23Jul 10, 2026 | CVSS9.6v3.1 | EPSS0.461% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Generated title:JetBrains IntelliJ IDEA UI Designer Form Parser XML External Entity InjectionIn JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible CWE-611May 29, 2026 | CVSS3.3v3.1 | EPSS0.109% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-49382MEDIUM | Generated title:JetBrains IntelliJ IDEA Copyright Plugin Template Injection Code ExecutionIn JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin CWE-1336May 29, 2026 | CVSS4.5v3.1 | EPSS0.135% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-49367HIGH | Generated title:JetBrains IntelliJ IDEA Missing Authorization Command Execution via Guest UserIn JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account CWE-862May 29, 2026 | CVSS8.0v3.1 | EPSS0.332% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-49366HIGH | Generated title:JetBrains IntelliJ IDEA Command Injection via Filename CompletionIn JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion CWE-78May 29, 2026 | CVSS7.8v3.1 | EPSS0.455% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-41882HIGH | Generated title:JetBrains IntelliJ IDEA Arbitrary Local File Read via Built-in Web ServerIn JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server CWE-59Apr 30, 2026 | CVSS7.4v3.1 | EPSS0.401% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-68269MEDIUM | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH CWE-349Dec 16, 2025 | CVSS5.4v3.1 | EPSS0.105% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-57730MEDIUM | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature CWE-80Aug 20, 2025 | CVSS5.2v3.1 | EPSS0.425% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-57729MEDIUM | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start CWE-829Aug 20, 2025 | CVSS6.5v3.1 | EPSS0.126% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-57728MEDIUM | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files CWE-863Aug 20, 2025 | CVSS6.5v3.1 | EPSS0.247% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-57727MEDIUM | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference CWE-319Aug 20, 2025 | CVSS4.7v3.1 | EPSS0.196% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file CWE-532Apr 3, 2025 | CVSS3.3v3.1 | EPSS0.413% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible CWE-79Sep 16, 2024 | CVSS3.3v3.1 | EPSS0.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-37051CRITICAL | GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7,… CWE-522Jun 10, 2024 | CVSS9.3v3.1 | EPSS3.84% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-24941MEDIUM | In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL CWE-20Feb 6, 2024 | CVSS6.1v3.1 | EPSS0.315% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives | CVSS2.8v3.1 | EPSS0.275% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-51655MEDIUM | In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration | CVSS6.3v3.1 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-39261MEDIUM | In JetBrains IntelliJ IDEA before 2023.2 plugin for Space was requesting excessive permissions CWE-250Jul 26, 2023 | CVSS5.2v3.1 | EPSS0.282% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
In JetBrains IntelliJ IDEA before 2023.1.4 license dialog could be suppressed in certain cases CWE-754Jul 12, 2023 | CVSS3.3v3.1 | EPSS0.173% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |