Executive brief
JetBrains IntelliJ IDEA, a popular software development environment, was vulnerable to a security flaw that allowed for unauthorized command execution. By tricking a user into interacting with a specially crafted filename during the auto-completion process, an attacker could run malicious code on the developer's computer. This could lead to the theft of source code, credentials, or full system compromise.
Technical details
A command injection vulnerability (CWE-78) existed in JetBrains IntelliJ IDEA prior to version 2026.1.1. The flaw was located in the filename completion component, where improper neutralization of special elements allowed for the execution of arbitrary OS commands. The attack vector is local and requires user interaction, specifically triggering filename completion on a malicious filename. Successful exploitation allows an attacker to execute commands with the privileges of the IDE user, potentially leading to full system compromise. The issue has been addressed in version 2026.1.1.
Affected products
- JetBrains IntelliJ IDEA Before 2026.1.1
Timeline
- 2026-05-29: advisory: CVE-2026-49366 published by JetBrains
- 2026-05-29: patched: Fixed in version 2026.1.1