Impact
JetBrains IntelliJ IDEA before version 2026.2.2 lacked a required project-trust check, allowing the IDE to expose sensitive project metadata to the JetBrains Marketplace. The missing check permits the leakage of structural and descriptive data about a project, potentially revealing its organization, coding patterns, and tool configuration. While the vulnerability does not grant code execution or privilege escalation, it compromises confidentiality by allowing external parties to obtain information that could be used for targeted attacks or competitive intelligence.
Affected Systems
Any installation of JetBrains IntelliJ IDEA with a version earlier than 2026.2.2 is susceptible. The issue affects all users who open or import projects that trigger the project-trust mechanism, without restriction to specific editions or deployment environments.
Risk and Exploitability
The CVSS score of 3.3 indicates a low severity risk, and the EPSS score is not available, which further suggests limited exploitation probability. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is local or remote use of the IDE when importing a project; an attacker would need access to the IDE environment or the ability to supply a specially crafted project to influence what metadata is exposed. The impact is limited to information disclosure and does not affect integrity or availability.
OpenCVE Enrichment