CVE-2025-57729
BaseFortify
Publication date: 2025-08-20
Last updated on: 2025-08-21
Assigner: JetBrains s.r.o.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jetbrains | intellij_idea | to 2025.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-829 | The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in JetBrains IntelliJ IDEA before version 2025.2 allows unexpected plugin startup due to the automatic start of the Language Server Protocol (LSP) server. This means that plugins could be started without explicit user action or consent, potentially leading to unintended behavior.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing unauthorized or unexpected plugins to start automatically, which could lead to high confidentiality and integrity risks, as well as some availability impact. This could result in exposure or modification of sensitive data and potential disruption of service.