7.4
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Description
In JetBrains IntelliJ IDEA before 2024.3.7.1,
2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-in web server
2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-in web server
Basic Information
ID
CVE-2026-41882
Source
JetBrains
Published
Apr 30, 2026 at 11:05
Affected Product
Vendor
JetBrains
Product
IntelliJ IDEA
Affected Versions
JetBrains IntelliJ IDEA 0