JetBrains JetBrains Creators of IntelliJ IDEA, ReSharper, PyCharm, TeamCity, Kotlin

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any JetBrains product.

RSS Feeds for JetBrains security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in JetBrains products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by JetBrains Sorted by Most Security Vulnerabilities since 2018

JetBrains Teamcity271 vulnerabilities

JetBrains Youtrack121 vulnerabilities

JetBrains Intellij Idea70 vulnerabilities

JetBrains Hub36 vulnerabilities

JetBrains Ktor21 vulnerabilities

JetBrains Toolbox10 vulnerabilities

JetBrains Pycharm9 vulnerabilities

JetBrains Webstorm9 vulnerabilities

JetBrains Goland8 vulnerabilities

JetBrains Rider7 vulnerabilities

JetBrains Kotlin7 vulnerabilities

JetBrains Phpstorm6 vulnerabilities

JetBrains Rubymine4 vulnerabilities

JetBrains Resharper2 vulnerabilities

JetBrains Clion2 vulnerabilities

JetBrains Mps2 vulnerabilities

JetBrains Junie1 vulnerability

JetBrains Rustrover1 vulnerability

JetBrains Dataspell1 vulnerability

JetBrains Datagrip1 vulnerability

JetBrains Aqua1 vulnerability

Known Exploited JetBrains Vulnerabilities

The following JetBrains vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
CVE-2026-63077
August 5, 2026
JetBrains TeamCity Relative Path Traversal Vulnerability JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.
CVE-2024-27199 Exploit Probability: 100.0%
April 20, 2026
JetBrains TeamCity Authentication Bypass Vulnerability JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
CVE-2024-27198 Exploit Probability: 99.9%
March 7, 2024
JetBrains TeamCity Authentication Bypass Vulnerability JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
CVE-2023-42793 Exploit Probability: 100.0%
October 4, 2023

Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 69 vulnerabilities in JetBrains with an average score of 6.9 out of ten. Last year, in 2025 JetBrains had 84 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in JetBrains in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.84.




Year Vulnerabilities Average Score
2026 69 6.91
2025 84 6.07
2024 103 6.20
2023 54 6.54
2022 75 6.48
2021 88 6.66
2020 57 6.38
2019 57 8.28
2018 2 0.00

It may take a day or so for new JetBrains vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent JetBrains Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-63077 Jul 27, 2026
JetBrains TeamCity <2026.1.3 Remote Code Execution via Agent Polling In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Teamcity
CVE-2026-65907 Jul 23, 2026
TeamCity <2026.1.2 Git VCS CodeExec Vulnerability In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
Teamcity
CVE-2026-65908 Jul 23, 2026
JetBrains PyCharm <2026.1.4, 2026.2 Arbitrary Exec via Malicious Python In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
Pycharm
CVE-2026-65906 Jul 23, 2026
TeamCity RCE via Kotlin DSL sandbox escape before 2026.1.2/2025.11.6 In JetBrains TeamCity before 2026.1.2, 2025.11.6 ode execution via Kotlin DSL sandbox escape was possible
Teamcity
CVE-2026-64815 Jul 23, 2026
IntelliJ IDEA UI Designer Form Files Code Injection <2026.2 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
Intellij Idea
CVE-2026-64814 Jul 23, 2026
IntelliJ IDEA <2026.2 Remote Dev Unauth File Access In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Intellij Idea
CVE-2026-64813 Jul 23, 2026
Unauthorized Settings Mod in IntelliJ IDEA <2026.2 Remote Dev In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Intellij Idea
CVE-2026-64812 Jul 23, 2026
IntelliJ IDEA <2026.2 unauthorized input injection in Remote Dev session In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
Intellij Idea
CVE-2026-64811 Jul 23, 2026
JetBrains IntelliJ IDEA <2026.2: Dev Cont Config Assignor ATE In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
Intellij Idea
CVE-2026-64810 Jul 23, 2026
JetBrains IntelliJ IDEA 2026.1: HTML Injection in IDE Notifications In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
Intellij Idea
CVE-2026-64809 Jul 23, 2026
JetBrains PhpStorm <2026.2 ACR via Interpreter Assigner In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
Phpstorm
CVE-2026-64808 Jul 23, 2026
PhpStorm <2026.2: Arbitrary Code Exec via Tooling Assigner In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
Phpstorm
CVE-2026-64807 Jul 23, 2026
WebStorm before 2026.2 arbitrary code exec via linter config assigner In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
Webstorm
CVE-2026-64806 Jul 23, 2026
JetBrains WebStorm <2026.2: Node.js Interpreter Assigner ATE In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter
Webstorm
CVE-2026-64805 Jul 23, 2026
JetBrains WebStorm <=2026.1: ATE via package-manager tooling In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling
Webstorm
CVE-2026-64804 Jul 23, 2026
JetBrains WebStorm <2026.2 ACE via Project-Local Linter Tooling In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling
Webstorm
CVE-2026-64803 Jul 23, 2026
JBL GoLand <=2026.1 ARC via Go SDK assigner In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
Goland
CVE-2026-64802 Jul 23, 2026
Arbitrary Code Exec in GoLand <2026.2 via Go Modules Trust In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
Goland
CVE-2026-64800 Jul 23, 2026
JetBrains GoLand <2026.2: Sensitive Config Logged (CVE-2026-64800) In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
Goland
CVE-2026-62422 Jul 14, 2026
Auth Bypass in JetBrains YouTrack <2026.1.13757 via Direct DB Access In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
Youtrack
CVE-2026-61492 Jul 10, 2026
JetBrains YouTrack XSS via article title in digest email before 2026.2.17394 In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
Youtrack
CVE-2026-59796 Jul 10, 2026
JetBrains TeamCity <2026.1.2: Pipeline Mod via Improper Perm Checks In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
Teamcity
CVE-2026-59795 Jul 10, 2026
TeamCity XSS via unauth agent reg before 2026.1.2 (JetBrains) In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
Teamcity
CVE-2026-59794 Jul 10, 2026
JetBrains TeamCity <2026.1.2 XSS via Agent Reported Data on Cloud Profile In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
Teamcity
CVE-2026-59793 Jul 10, 2026
TeamCity < 2026.1.2 Perforce VCS arbitrary file access In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
Teamcity
CVE-2026-59792 Jul 10, 2026
JetBrains IntelliJ IDEA <2026.1.4: Path Traversal Exec via Workspace ID In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
Intellij Idea
CVE-2026-59791 Jul 10, 2026
YouTrack <2026.2.17012: CSS Injection via Mermaid Diagram In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
Youtrack
CVE-2026-53914 Jun 26, 2026
JetBrains Kotlin <2.4.20 Uns. Deser. in Build Cache Metadata Assigner In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Kotlin
CVE-2026-57926 Jun 26, 2026
Prototype Pollution in JetBrains YouTrack before 2026.2.16593 Websandbox Bridge In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Youtrack
CVE-2026-57925 Jun 26, 2026
YouTrack <2026.2.16593 Improper Access Control Read Queries & Tags In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
Youtrack
CVE-2026-57924 Jun 26, 2026
YouTrack <=2026.2.16593 Default Role Config Exposes User Profile Details In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
Youtrack
CVE-2026-57923 Jun 26, 2026
YouTrack <2026.2.16593 Improper Auth on App Config Endpoint In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
Youtrack
CVE-2026-57922 Jun 26, 2026
JetBrains YouTrack 2026.2.16593 Project Settings Disclosure via MCP In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Youtrack
CVE-2026-57921 Jun 26, 2026
YouTrack <2026.2.16593 Improper Access: Read Private Data via Comment Templates In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
Youtrack
CVE-2026-56142 Jun 19, 2026
Privilege Escalation in JetBrains Hub <2026.1.13757 via Auth Details Attach In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible
Hub
CVE-2026-50242 Jun 19, 2026
JetBrains Hub <2026.1.13757 Auth bypass via DB access In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
Hub
CVE-2026-56141 Jun 19, 2026
Account takeover via predictable restore codes in JetBrains Hub before 2026.1.13757 In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible
Hub
CVE-2026-53915 Jun 19, 2026
GoLand RCE via Untrusted Assigner in Project Config before 2026.1.3 (JetBrains) In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
Goland
CVE-2026-49386 May 29, 2026
Improper Access Control in JetBrains YouTrack <2026.1.13570 (Planning Canvas) In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
Youtrack
CVE-2026-49385 May 29, 2026
YouTrack <2026.1.13570 Improper ACL: Low-Privileged Modifies Service Accounts In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
Youtrack
CVE-2026-49384 May 29, 2026
PyCharm <2025.3.4 Stored XSS via Jupyter Markdown In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
Pycharm
CVE-2026-49383 May 29, 2026
JETBRAINS INTELLIJ IDEA <2026.1 UI Designer XXE in Form Parser In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
Intellij Idea
CVE-2026-49382 May 29, 2026
IntelliJ IDEA <2026.1: Template Injection Exec CVE-2026-49382 In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
Intellij Idea
CVE-2026-49381 May 29, 2026
TeamCity XSS via Stored SAML login before 2026.1 In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
Teamcity
CVE-2026-49379 May 29, 2026
Thread Names Assigner Exposes Credentials in JetBrains TeamCity <2026.1 In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
Teamcity
CVE-2026-49378 May 29, 2026
JetBrains TeamCity <=2026.1 Credential Exposure via Autocomplete In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
Teamcity
CVE-2026-49380 May 29, 2026
JetBrains TeamCity <2026.1 SAML Plugin Open Redirect In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
Teamcity
CVE-2026-49377 May 29, 2026
JetBrains TeamCity <=2025.11.1 Default Agent Params expose sensitive data In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
Teamcity
CVE-2026-49376 May 29, 2026
TeamCity<2026.1 Insufficient Username Validation in SAML Plugin Assigner In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
Teamcity
CVE-2026-49375 May 29, 2026
JetBrains TeamCity <2026.1 Reflected XSS on Repo Download Page In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
Teamcity
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.