Executive brief
IntelliJ IDEA, a popular integrated development environment used by developers to write and debug code, was storing Git authentication credentials in plaintext within its debug logs. An attacker with local access to a developer's machine could retrieve these logs and obtain the Git credentials, potentially allowing unauthorized access to source code repositories and sensitive development infrastructure.
Technical details
The vulnerability is a credential exposure issue where JetBrains IntelliJ IDEA writes Git authentication credentials in plaintext to the IDE's diagnostic log files. The vulnerable component is the Git integration module that handles credential management during repository operations. The attack vector is local—an attacker requires filesystem access to the IDE's log directory on the developer's machine to exploit this. No authentication or network access is required. An attacker can retrieve plaintext credentials from the logs and use them to authenticate to Git repositories. The issue is fixed in IntelliJ IDEA 2026.1.5 and later versions.
Affected products
- JetBrains IntelliJ IDEA before 2026.1.5
Timeline
- 2026-08-17: disclosed
- 2026-01-17: patched: Fixed in version 2026.1.5