Impact
Git credentials were written in plain text to JetBrains IntelliJ IDEA logs in versions prior to 2026.1.5. This flaw allows an attacker who can read the IDE log files to obtain user credentials that may grant access to remote Git repositories. The weakness, captured by CWE‑532, exposes sensitive data without altering the system’s functionality or availability.
Affected Systems
JetBrains IntelliJ IDEA products released before version 2026.1.5 are affected. Systems running those releases will log Git credentials as clear‑text entries in the IDE’s log directory.
Risk and Exploitability
The CVSS score of 6.2 indicates moderate severity; no EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is local: an adversary must have the capability to read the IDE log files or otherwise access the file system. The impact is confined to information disclosure; however, compromised credentials can lead to unauthorized access to code repositories and can be leveraged further by an attacker.
OpenCVE Enrichment