Impact
An untrusted project file can cause JetBrains IntelliJ IDEA to fetch a Kubernetes spec-source URL, resulting in a server-side request forgery that may expose internal network resources or sensitive data. The weakness is identified as CWE‑918: Server-side Request Forgery. The impact is limited to information disclosure and potential internal resource exploitation rather than immediate remote code execution.
Affected Systems
JetBrains IntelliJ IDEA versions prior to 2026.2.2 are vulnerable. Users running these versions should note that any untrusted project opened during the development session can trigger the SSRF behavior.
Risk and Exploitability
The CVSS score of 3.3 indicates low overall severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is currently low; however, the vulnerability can be triggered by an attacker who can supply a malicious project file. The attack vector is inferred to be local (within the user’s development environment) or via social engineering of a teammate.
OpenCVE Enrichment