Impact
The flaw resides in the Markdown export tool of JetBrains IntelliJ IDEA versions earlier than 2026.2.1. When a specially crafted Markdown document is processed, it can cause the IDE to execute arbitrary code, giving the attacker full control of the host system. This issue is classified as a remote code execution vulnerability.
Affected Systems
JetBrains IntelliJ IDEA users on any operating system running a version before 2026.2.1 are vulnerable. The affected builds are those identified as IntelliJ IDEA 2026.2 and earlier. No additional vendors or products are known to be impacted.
Risk and Exploitability
The CVSS base score of 7.8 indicates moderate to high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely leveraged in the wild. The attack appears to require the user to open a malicious Markdown file and invoke the export function, which may limit exploitation to users with sufficient access or through social engineering.
OpenCVE Enrichment