Executive brief
JetBrains IntelliJ IDEA is a widely-used integrated development environment (IDE) for software developers. An XML external entity (XXE) vulnerability in the Eclipse settings importer allows an attacker to process malicious XML files, potentially leading to disclosure of sensitive files or denial of service when developers import Eclipse project settings.
Technical details
An XML External Entity (XXE) injection vulnerability exists in JetBrains IntelliJ IDEA's Eclipse settings importer component. The vulnerable code fails to disable XML external entity resolution when parsing Eclipse configuration files, allowing an attacker to craft malicious Eclipse settings that, when imported by a developer, can lead to arbitrary file disclosure or denial of service. The attack requires user interaction (importing a malicious Eclipse settings file) but no authentication. The vulnerability affects versions prior to 2026.2.1; a patch is available in the fixed release.
Affected products
- JetBrains IntelliJ IDEA before 2026.2.1
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched: Fixed in version 2026.2.1