Impact
The vulnerability exposes JetBrains IntelliJ IDEA to server‑side request forgery (SSRF) via the OpenAPI preview proxy when the IDE processes untrusted project files. Attackers could potentially instruct the IDE to perform arbitrary HTTP requests from the host machine, leaking internal secrets or facilitating further network attacks. The weakness is classified as CWE‑918, indicating the improper validation of URLs before performing outbound network requests. The effect is a compromise of confidentiality and integrity for the machine running the IDE, and could be a stepping stone for more severe exploits.
Affected Systems
JetBrains IntelliJ IDEA versions prior to 2026.2.1 are affected. Only the JetBrains product is implicated; later releases include the fix.
Risk and Exploitability
The CVSS score of 6.3 marks it as high‑severity, while the EPSS score is currently unavailable but the issue is not listed in KEV. The attack vector is inferred to be Local or Remote depending on how untrusted project files are introduced, with no active exploits noted. The risk is moderate to high, especially for environments that routinely import untrusted projects or expose the IDE to networked clients.
OpenCVE Enrichment