Impact
The vulnerability allows an attacker to execute arbitrary code within the IntelliJ IDEA process before the project is granted trust through the development container configuration. This weakness is classified as CWE‑829, indicating an improper restriction of operations within the bounds of a resource. An attacker who can influence the development container configuration could run code with the same privileges as the IDE, potentially leading to full compromise of the host system.
Affected Systems
JetBrains IntelliJ IDEA versions released before 2026.2 are affected. All earlier releases, including 2025.x and prior, are susceptible to the described exploitation path.
Risk and Exploitability
The CVSS score of 7.8 marks this as a high‑severity flaw, while the EPSS score of less than 1% indicates a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector appears to be local or requires an attacker to influence the IDE’s configuration; direct remote exploitation is not documented.
OpenCVE Enrichment