Description
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
Published: 2026-07-23
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In versions of JetBrains IntelliJ IDEA prior to 2026.2, a flaw in the handling of HTML content within IDE notifications allows an attacker to inject arbitrary HTML. This injection can be used to silently monitor or record user activity without their knowledge. The vulnerability is classified as a typical client‑side injection flaw (CWE‑79).

Affected Systems

The affected product is JetBrains IntelliJ IDEA. Any installation of IntelliJ IDEA that has not been updated to version 2026.2 or later is potentially vulnerable. No additional version details beyond the pre‑2026.2 baseline are provided.

Risk and Exploitability

The assigned CVSS score of 4.3 indicates moderate severity, while the EPSS value of less than 1 % suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of malicious content through an IDE notification, possibly via a compromised plugin or an external trigger that causes the notification to display user data. Exploitation would enable covert tracking of user actions but does not provide direct code‑execution or privilege‑escalation capabilities.

Generated by OpenCVE AI on August 4, 2026 at 15:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade IntelliJ IDEA to version 2026.2 or later, removing the injection flaw.
  • Configure the IDE to disallow HTML rendering in notification messages to block further injection attempts.
  • Remove or scrutinize plugins that can trigger notification content and disable any that appear suspicious.

Generated by OpenCVE AI on August 4, 2026 at 15:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title HTML Injection Allows Silent User Activity Tracking in IntelliJ IDEA

Sun, 02 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title HTML Injection Allows Silent User Activity Tracking in IntelliJ IDEA

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title HTML Injection in IntelliJ IDEA Notification Enables Silent User Activity Tracking

Mon, 27 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title HTML Injection in IntelliJ IDEA Notification Enables Silent User Activity Tracking

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains intellij Idea
Vendors & Products Jetbrains
Jetbrains intellij Idea

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Jetbrains Intellij Idea
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-23T13:20:00.344Z

Reserved: 2026-07-20T18:20:29.976Z

Link: CVE-2026-64810

cve-icon Vulnrichment

Updated: 2026-07-23T13:19:57.304Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T12:18:36.553

Modified: 2026-07-28T17:09:16.960

Link: CVE-2026-64810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')