CVE-2026-41882

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
30/04/2026
Last modified:
05/05/2026

Description

In JetBrains IntelliJ IDEA before 2024.3.7.1, <br /> 2025.1.7.1,<br /> 2025.2.6.2, <br /> 2025.3.4.1, <br /> 2026.1.1 reading arbitrary local files was possible via built-in web server

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jetbrains:intellij_idea:2024.3.7.1:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:intellij_idea:2025.1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:intellij_idea:2025.2.6.2:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:intellij_idea:2025.3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:intellij_idea:2026.1.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools