Impact
JetBrains IntelliJ IDEA records terminal command history into the idea.log file when using versions older than 2026.2.2. This results in sensitive information such as command arguments or environment data being written to a log that could be accessed by local users or other processes with read access to the IDE workspace, potentially revealing secrets or developer credentials. The vulnerability is a low‑scoring flaw (CVSS 2.8) that provides harmful information disclosure without granting execution or unauthorized control.
Affected Systems
The issue affects JetBrains IntelliJ IDEA installations prior to the 2026.2.2 release. All users running the IDE on any supported platform with the terminal plugin enabled are at risk. No specific operating system or plug‑in version beyond the pre‑2026.2.2 release is required for the vulnerability to be present.
Risk and Exploitability
The CVSS score reflects a modest risk level and the EPSS value is unavailable, indicating no evidence of recent exploitation activity. The flaw is not listed in CISA’s KEV catalog. The likely attack vector is local: any user with access to the IDE can observe the terminal history captured in idea.log, or an attacker who gains local file‑system access could read the log. No special privileges or remote access are required for exploitation beyond normal IDE use.
OpenCVE Enrichment