Executive brief
JetBrains IntelliJ IDEA, a popular development environment used by software engineers, was vulnerable to a security flaw in its UI Designer component. An attacker could potentially execute unauthorized code on a developer's machine by providing a specially crafted form file. This could lead to a full system compromise, theft of source code, or unauthorized access to corporate development environments.
Technical details
A code injection vulnerability (CWE-94) exists in JetBrains IntelliJ IDEA's UI Designer component. The flaw stems from improper control of code generation when processing UI Designer form files (.form). An attacker can exploit this by providing a malicious form file that, when processed by the IDE, executes arbitrary commands. While the attack vector is listed as network-based, it typically requires a high complexity (AC:H) precondition, likely involving the victim opening or importing a malicious project or file. Successful exploitation allows for full remote code execution (RCE) with the privileges of the IDE user. The issue is resolved in version 2026.2.
Affected products
- JetBrains IntelliJ IDEA before 2026.2
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory