Impact
Based on the description, it is inferred that the attacker can manipulate project workspace IDs in Intelli code execution. An attacker can exploit a path traversal flaw in IntelliJ IDEA’s handling of project workspace IDs to execute arbitrary code on the host system. The weakness, identified as CWE-23, allows malicious users to craft a project file or input that resolves to an absolute path IDE running arbitrary code. This can lead to full compromise of the machine where the IDE is running.
Affected Systems
JetBrains IntelliJ IDEA versions released before 2026.1.4 and the 2026.2 release are affected. The flaw platform variants of IntelliJ IDEA and is not mitigated in earlier releases.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector involves an attacker providing a crafted project or workspace ID while the IDE is running. With a CVSS score of 9.6, the vulnerability is considered critical. The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild, yet the lack of such data does not reduce the risk because the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the IDE to be running and a user or an external process to supply a crafted project or workspace ID.
OpenCVE Enrichment