Impact
In JetBrains PyCharm versions earlier than 2026.2.1 an attacker could abuse the Quick Documentation feature to execute arbitrary code on the system running the IDE. The vulnerability allows local code execution and is classified as a CWE-79 type weakness. An exploitable instance would let a user or a malicious plug‑in trigger the execution flow, resulting in full control over the affected machine.
Affected Systems
The affected product is JetBrains PyCharm. Versions before 2026.2.1 are impacted; the fix was released in the 2026.2.1 release. Any user still running an older edition of PyCharm is potentially vulnerable.
Risk and Exploitability
The CVSS score for this vulnerability is 4.4, indicating moderate severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The attack vector is locally exploitable, likely through the user interface when Quick Documentation is invoked. Because the flaw requires interaction within the IDE, the risk is limited to users who can control the environment where PyCharm is running. No publicly available exploits have been reported at the time of this analysis.
OpenCVE Enrichment