Junglewise Threat Intelligence

CVE-2026-75059: JetBrains PyCharm code execution via Quick Documentation

CVE-2026-75059 · Severity: medium · CVSS 4.4 · Published 2026-08-17

Technologies: Jetbrains PyCharm. Vendors: Jetbrains.

Executive brief

PyCharm is a widely-used Python development environment from JetBrains. A vulnerability in the Quick Documentation feature could allow an attacker to execute arbitrary code within the IDE, potentially compromising developer machines and the source code and credentials they contain. This poses a risk to development teams using affected versions.

Technical details

The vulnerability is a code execution flaw in PyCharm's Quick Documentation feature (CVE-2026-75059). The exact root cause and attack vector are not fully detailed in the advisory, but the issue affects versions before 2026.2.1 and allows arbitrary code execution. The attack likely requires local access or user interaction (e.g., hovering over or viewing documentation for malicious code). JetBrains has released a patch in version 2026.2.1 or later.

Affected products

  • JetBrains PyCharm before 2026.2.1

Timeline

  • 2026-08-17: disclosed
  • 2026-2026.: patched

References

Related threats