In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
JetBrains CVEs
58 high and critical vulnerabilities covered by CVE Brief since 2025-07-15, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
50 CVEs in the last 12 months
Products
- YouTrack17
- TeamCity12
- IntelliJ IDEA10
- Hub4
- WebStorm4
- PyCharm3
- PhpStorm2
- GoLand2
11 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development...
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permi...
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
JetBrains Hub contains a flaw allowing unauthenticated attackers to register a trusted service, resulting in the acquisition of superuser privileges.
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDO...
An improper authentication vulnerability in the JetBrains YouTrack Helpdesk feature allows unauthenticated attackers to perform account takeovers by s...
In JetBrains PyCharm before 2026
In JetBrains IntelliJ IDEA before 2026
In JetBrains YouTrack before 2026
In JetBrains YouTrack before 2026
JetBrains YouTrack is vulnerable to unauthorized database backup downloads by unauthenticated attackers due to an issue with shared draft signatures.
In JetBrains YouTrack before 2025
In JetBrains PyCharm before 2026
In JetBrains TeamCity before 2026
In JetBrains IntelliJ IDEA before 2026
In JetBrains IntelliJ IDEA before 2026
JetBrains IntelliJ IDEA is vulnerable to unauthorized settings modification during Remote Development sessions, enabling unauthenticated attackers to...
JetBrains IntelliJ IDEA is susceptible to unauthorized input injection during Remote Development sessions, allowing unauthenticated remote attackers t...
In JetBrains IntelliJ IDEA before 2026
In JetBrains PhpStorm before 2026
In JetBrains PhpStorm before 2026
In JetBrains WebStorm before 2026
In JetBrains WebStorm before 2026
In JetBrains WebStorm before 2026
In JetBrains WebStorm before 2026
In JetBrains GoLand before 2026
In JetBrains GoLand before 2026
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
JetBrains YouTrack is affected by an authentication bypass vulnerability allowing unauthenticated attackers to gain administrative access via direct d...
In JetBrains TeamCity before 2026
In JetBrains TeamCity before 2026
In JetBrains TeamCity before 2026
In JetBrains TeamCity before 2026
JetBrains IntelliJ IDEA is vulnerable to remote code execution due to path traversal in project workspace ID handling.
JetBrains Hub is susceptible to privilege escalation by allowing the attachment of unauthorized authentication details to user accounts.
JetBrains Hub contains an authentication bypass vulnerability via direct database access that allows unauthorized administrative control.
In JetBrains YouTrack before 2026
In JetBrains TeamCity before 2026
In JetBrains IntelliJ IDEA before 2024
In JetBrains YouTrack before 2025
In JetBrains YouTrack before 2025
JetBrains Hub versions prior to 2025.3.119807 contain an authentication bypass vulnerability that allows unauthenticated attackers to perform administ...
In JetBrains PyCharm before 2025
In JetBrains YouTrack before 2025.3.104432 misconfiguration in the Junie could lead to exposure of the global Junie token
In JetBrains YouTrack before 2025
In JetBrains ReSharper before 2025
In JetBrains Junie before 252
In JetBrains TeamCity before 2025
In JetBrains IDE Services before 2025
In JetBrains TeamCity before 2025
In JetBrains YouTrack before 2025
In JetBrains TeamCity before 2025
In JetBrains TeamCity before 2025
In JetBrains YouTrack before 2025
JetBrains TeamCity Relative Path Traversal Vulnerability - Active in CISA KEV catalog.