Executive brief
JetBrains IntelliJ IDEA, a popular software development environment, was vulnerable to a flaw that allowed malicious HTML to be injected into IDE notifications. If a developer interacted with a specially crafted notification, an attacker could silently track their activity within the tool. This could lead to the exposure of sensitive workflow information or usage patterns to unauthorized parties.
Technical details
A vulnerability classified as HTML injection (CWE-79) existed in JetBrains IntelliJ IDEA versions prior to 2026.2. The flaw resided in the handling of IDE notifications, where improper neutralization of input allowed for the injection of arbitrary HTML content. An attacker could leverage this to embed tracking elements (such as remote images or scripts) that trigger when a user views or interacts with the notification. Exploitation requires network delivery of the malicious payload and user interaction. The primary impact is a loss of confidentiality regarding user activity tracking.
Affected products
- JetBrains IntelliJ IDEA before 2026.2
Timeline
- 2026-07-23: advisory: NVD publication date
- 2026-07-23: disclosed: Initial disclosure by JetBrains