CVE-2026-41882
Analyzed
Analyzed - Analysis Complete
Arbitrary File Read in JetBrains IntelliJ IDEA
Publication date: 2026-04-30
Last updated on: 2026-05-05
Assigner: JetBrains s.r.o.
Description
Description
In JetBrains IntelliJ IDEA before 2024.3.7.1,
2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-in web server
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jetbrains | intellij_idea | 2024.3.7.1 |
| jetbrains | intellij_idea | 2025.1.7.1 |
| jetbrains | intellij_idea | 2025.2.6.2 |
| jetbrains | intellij_idea | 2025.3.4.1 |
| jetbrains | intellij_idea | 2026.1.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-59 | The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource. |