Intellij idea
This hub aggregates every CVE we track for Intellij idea, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
69
CVEs tracked
10
Critical
19
High
0
In CISA KEV
Severity distribution
MEDIUM28HIGH19LOW12CRITICAL10
Monthly trend
1
0
0
0
0
0
0
1
0
0
0
4
0
0
0
1
0
0
0
1
4
0
7
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Intellij idea.
- CVE-2026-64815In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files8.1
- CVE-2026-64814In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session8.6
- CVE-2026-64812In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session10.0
- CVE-2026-64811In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration7.8
- CVE-2026-64813In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session10.0
- CVE-2026-64810In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking4.3
- CVE-2026-59792In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible9.6
- CVE-2026-49383In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible3.3
- CVE-2026-49382In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin4.5
- CVE-2026-49367In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account8.0
- CVE-2026-49366In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion7.8
- CVE-2026-41882In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server7.4
- CVE-2025-68269In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH5.4
- CVE-2025-57730In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature5.2
- CVE-2025-57729In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start6.5
Product normalization is registry-driven with AI assist and human review. How it works