Description
In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project workspace ID handling was possible
Published: 2026-07-10
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the attacker can manipulate project workspace IDs in Intelli code execution. An attacker can exploit a path traversal flaw in IntelliJ IDEA’s handling of project workspace IDs to execute arbitrary code on the host system. The weakness, identified as CWE-23, allows malicious users to craft a project file or input that resolves to an absolute path IDE running arbitrary code. This can lead to full compromise of the machine where the IDE is running.

Affected Systems

JetBrains IntelliJ IDEA versions released before 2026.1.4 and the 2026.2 release are affected. The flaw platform variants of IntelliJ IDEA and is not mitigated in earlier releases.

Risk and Exploitability

Based on the description, it is inferred that the likely attack vector involves an attacker providing a crafted project or workspace ID while the IDE is running. With a CVSS score of 9.6, the vulnerability is considered critical. The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild, yet the lack of such data does not reduce the risk because the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the IDE to be running and a user or an external process to supply a crafted project or workspace ID.

Generated by OpenCVE AI on July 28, 2026 at 08:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update IntelliJ IDEA to version 2026.1.4 or later, which removes the path traversal flaw.
  • Until the update is applied, avoid opening or cloning projects from untrusted sources and refrain from loading potentially crafted project files.
  • Restrict or monitor any external processes that can programmatically set workspace IDs to limit their ability to inject malicious paths during IDE workspace migration.

Generated by OpenCVE AI on July 28, 2026 at 08:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title IntelliJ IDEA Path Traversal in Workspace ID Allows Remote Code Execution

Thu, 23 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title IntelliJ IDEA Path Traversal in Workspace ID Allows Remote Code Execution

Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in IntelliJ IDEA Workspace ID Handling

Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in IntelliJ IDEA Workspace ID Handling

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in IntelliJ IDEA Enables Remote Code Execution

Mon, 13 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Path Traversal Vulnerability in IntelliJ IDEA Enables Remote Code Execution

Sun, 12 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Exploit in IntelliJ IDEA Project Workspace ID Handling

Sat, 11 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Exploit in IntelliJ IDEA Project Workspace ID Handling

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains intellij Idea
Vendors & Products Jetbrains
Jetbrains intellij Idea

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L'}


Subscriptions

Jetbrains Intellij Idea
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-14T03:55:40.249Z

Reserved: 2026-07-07T09:41:07.385Z

Link: CVE-2026-59792

cve-icon Vulnrichment

Updated: 2026-07-10T15:44:31.482Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses
  • CWE-23

    Relative Path Traversal