Junglewise Threat Intelligence

CVE-2026-49366: JetBrains IntelliJ IDEA command injection in filename completion

CVE-2026-49366 · Severity: high · CVSS 7.8 · Published 2026-05-29

Technologies: Jetbrains IntelliJ IDEA. Vendors: Jetbrains.

Executive brief

JetBrains IntelliJ IDEA, a popular software development environment, was vulnerable to a security flaw that allowed for unauthorized command execution. By tricking a user into interacting with a specially crafted filename during the auto-completion process, an attacker could run malicious code on the developer's computer. This could lead to the theft of source code, credentials, or full system compromise.

Technical details

A command injection vulnerability (CWE-78) existed in JetBrains IntelliJ IDEA prior to version 2026.1.1. The flaw was located in the filename completion component, where improper neutralization of special elements allowed for the execution of arbitrary OS commands. The attack vector is local and requires user interaction, specifically triggering filename completion on a malicious filename. Successful exploitation allows an attacker to execute commands with the privileges of the IDE user, potentially leading to full system compromise. The issue has been addressed in version 2026.1.1.

Affected products

  • JetBrains IntelliJ IDEA Before 2026.1.1

Timeline

  • 2026-05-29: advisory: CVE-2026-49366 published by JetBrains
  • 2026-05-29: patched: Fixed in version 2026.1.1

References

Related threats