Executive brief
JetBrains PyCharm is an integrated development environment (IDE) for Python development. A vulnerability in its Jupyter MCP (Model Context Protocol) tools implementation allowed unauthenticated remote attackers to execute arbitrary code on systems running PyCharm before version 2026.2.1, potentially compromising developer machines and any code or credentials they access.
Technical details
The vulnerability exists in PyCharm's Jupyter MCP tools implementation, which failed to properly authenticate requests before executing code. The lack of authentication controls on the MCP tools allowed remote attackers to send malicious requests over the network to execute arbitrary code with the privileges of the PyCharm process. No user interaction or prior authentication is required; an attacker with network access to a vulnerable PyCharm instance can directly trigger code execution. The vulnerability was resolved in PyCharm version 2026.2.1 and later.
Affected products
- JetBrains PyCharm before 2026.2.1
Timeline
- 2026-08-17: disclosed