Impact
In versions of JetBrains IntelliJ IDEA prior to 2026.2, a flaw in the handling of HTML content within IDE notifications allows an attacker to inject arbitrary HTML. This injection can be used to silently monitor or record user activity without their knowledge. The vulnerability is classified as a typical client‑side injection flaw (CWE‑79).
Affected Systems
The affected product is JetBrains IntelliJ IDEA. Any installation of IntelliJ IDEA that has not been updated to version 2026.2 or later is potentially vulnerable. No additional version details beyond the pre‑2026.2 baseline are provided.
Risk and Exploitability
The assigned CVSS score of 4.3 indicates moderate severity, while the EPSS value of less than 1 % suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of malicious content through an IDE notification, possibly via a compromised plugin or an external trigger that causes the notification to display user data. Exploitation would enable covert tracking of user actions but does not provide direct code‑execution or privilege‑escalation capabilities.
OpenCVE Enrichment