CVE-2026-100265
Awaiting Analysis Awaiting Analysis - Queue

AI Assistant Skill Auto-Update in JetBrains Rider

Vulnerability report for CVE-2026-100265, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: JetBrains s.r.o.

Description

In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jetbrains rider to 2026.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in JetBrains Rider before 2026.2.1 allows the AI Assistant feature to automatically update third-party skills without requiring user confirmation. This could lead to unintended changes or malicious modifications being applied to the IDE's functionality.

Impact Analysis

The vulnerability may allow unauthorized or malicious third-party skills to be installed, potentially compromising the integrity of your development environment. This could lead to data leaks, code manipulation, or other security risks in your projects.

Compliance Impact

The vulnerability allows auto-updates of third-party skills without user confirmation, which could lead to unauthorized code execution or data exposure. This may violate GDPR's requirement for explicit user consent and HIPAA's controls on software integrity and access management.

Mitigation Strategies

Update JetBrains Rider to version 2026.2.1 or later to address the vulnerability in aI Assistant.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100265. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart