Description
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
Published: 2026-08-17
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In JetBrains PyCharm versions earlier than 2026.2.1 an attacker could abuse the Quick Documentation feature to execute arbitrary code on the system running the IDE. The vulnerability allows local code execution and is classified as a CWE-79 type weakness. An exploitable instance would let a user or a malicious plug‑in trigger the execution flow, resulting in full control over the affected machine.

Affected Systems

The affected product is JetBrains PyCharm. Versions before 2026.2.1 are impacted; the fix was released in the 2026.2.1 release. Any user still running an older edition of PyCharm is potentially vulnerable.

Risk and Exploitability

The CVSS score for this vulnerability is 4.4, indicating moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The attack vector is locally exploitable, likely through the user interface when Quick Documentation is invoked. Because the flaw requires interaction within the IDE, the risk is limited to users who can control the environment where PyCharm is running. No publicly available exploits have been reported at the time of this analysis.

Generated by OpenCVE AI on August 17, 2026 at 17:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains PyCharm to version 2026.2.1 or later, which contains the fix for this vulnerability.
  • If an upgrade is not immediately possible, disable or remove the Quick Documentation feature within PyCharm to prevent exploitation.
  • Ensure that any third‑party plug‑ins that invoke Quick Documentation are updated or removed, and monitor JetBrains security advisories for additional guidance.

Generated by OpenCVE AI on August 17, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Code Execution via PyCharm Quick Documentation in Pre‑2026.2.1 Versions

Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains pycharm
Vendors & Products Jetbrains
Jetbrains pycharm

Mon, 17 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Jetbrains Pycharm
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-08-18T03:55:37.215Z

Reserved: 2026-08-17T15:34:11.533Z

Link: CVE-2026-75059

cve-icon Vulnrichment

Updated: 2026-08-17T16:14:56.245Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-17T16:17:53.110

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-75059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T18:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')