JetBrains Creators of IntelliJ IDEA, ReSharper, PyCharm, TeamCity, Kotlin
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any JetBrains product.
RSS Feeds for JetBrains security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in JetBrains products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by JetBrains Sorted by Most Security Vulnerabilities since 2018
Known Exploited JetBrains Vulnerabilities
The following JetBrains vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| JetBrains TeamCity Authentication Bypass Vulnerability |
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. CVE-2024-27198 Exploit Probability: 94.6% |
March 7, 2024 |
| JetBrains TeamCity Authentication Bypass Vulnerability |
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. CVE-2023-42793 Exploit Probability: 92.9% |
October 4, 2023 |
Of the known exploited vulnerabilities above, 2 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 0 vulnerabilities in JetBrains. Last year, in 2025 JetBrains had 83 security vulnerabilities published. Right now, JetBrains is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 83 | 6.03 |
| 2024 | 103 | 6.20 |
| 2023 | 54 | 6.54 |
| 2022 | 75 | 6.48 |
| 2021 | 88 | 6.66 |
| 2020 | 57 | 6.52 |
| 2019 | 57 | 7.08 |
| 2018 | 1 | 7.80 |
It may take a day or so for new JetBrains vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent JetBrains Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2025-68269 | Dec 16, 2025 |
JetBrains IntelliJ IDEA <2025.3: SSH Remote Project Confirmation BypassIn JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH |
|
| CVE-2025-68268 | Dec 16, 2025 |
TeamCity Reflected XSS (Storage Settings) before 2025.11.1In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page |
|
| CVE-2025-68267 | Dec 16, 2025 |
JetBrains TeamCity < 2025.11.1: GitHub PA Token Stored Privilege EscalationIn JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token |
|
| CVE-2025-68166 | Dec 16, 2025 |
JetBrains TeamCity <=2025.10 DOM XSS on OAuth Connections TabIn JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab |
|
| CVE-2025-68165 | Dec 16, 2025 |
JetBrains TeamCity pre-2025.11: VCS Root setup Reflected XSSIn JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup |
|
| CVE-2025-68164 | Dec 16, 2025 |
JetBrains TeamCity Port Enumeration via Perforce Conn Test (pre-2025.11)In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test |
|
| CVE-2025-68163 | Dec 16, 2025 |
TeamCity <2025.11: stored XSS on agentpushInstall pageIn JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page |
|
| CVE-2025-68162 | Dec 16, 2025 |
TeamCity <2025.11: Maven Embedder allows Unrestricted Extension LoadingIn JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration |
|
| CVE-2025-67742 | Dec 11, 2025 |
TeamCity < 2025.11 Path Traversal via File Upload (CVE-2025-67742)In JetBrains TeamCity before 2025.11 path traversal was possible via file upload |
|
| CVE-2025-67741 | Dec 11, 2025 |
JetBrains TeamCity 2025.10 Stored XSS via session attributeIn JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute |
|
| CVE-2025-67740 | Dec 11, 2025 |
JetBrains TeamCity <2025.11: Improper Access Control Exposes GH Token MetadataIn JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata |
|
| CVE-2025-67739 | Dec 11, 2025 |
JetBrains TeamCity <2025.11.2 Rp URL Validation flaw => Local Path DisclosureIn JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure |
|
| CVE-2025-64773 | Nov 11, 2025 |
YouTrack <2025.3.104432 Race Condition Bypass Helpdesk Agent LimitIn JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit |
|
| CVE-2025-64457 | Nov 10, 2025 |
dotTrace before 2025.2.5 Local Priv Esc via Race ConditionIn JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition |
|
| CVE-2025-64456 | Nov 10, 2025 |
ReSharper DPA Collector LPE before 2025.2.4In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation |
|
| CVE-2025-64690 | Nov 10, 2025 |
JetBrains YouTrack <2025.3.104432 insecure Junie config: data exfil + auth chg |
|
| CVE-2025-64689 | Nov 10, 2025 |
YouTrack <=2025.3.104432 Junie Token Leak via Misconfig |
|
| CVE-2025-64688 | Nov 10, 2025 |
JetBrains YouTrack <2025.3.104432 URL Validation Flaw: Unauthorized Repo Access |
|
| CVE-2025-64687 | Nov 10, 2025 |
JetBrains YouTrack <2025.3.104432 Improper Access Control in MCP Logic |
|
| CVE-2025-64686 | Nov 10, 2025 |
YouTrack<2025.3.104432: Auth Context Reuse via Missing Principal Cleanup |
|
| CVE-2025-64685 | Nov 10, 2025 |
YouTrack TLS Cert Validation Bypass CVE-2025-64685 (pre 2025.3.104432)In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure |
|
| CVE-2025-64684 | Nov 10, 2025 |
CVE-2025-64684: YouTrack < 2025.3.104432 Info Disclosure via Feedback FormIn JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form |
|
| CVE-2025-64683 | Nov 10, 2025 |
JetBrains Hub <2025.3.104432: Users API Info DisclosureIn JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API |
|
| CVE-2025-64682 | Nov 10, 2025 |
JetBrains Hub Before 2025.3.104432: Race Condition Allows Agent-User Limit BypassIn JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit |
|
| CVE-2025-64681 | Nov 10, 2025 |
JetBrains Hub <2025.3.104992: Race Cond Bypass Invite User LimitIn JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations |
|
| CVE-2025-59458 | Sep 17, 2025 |
Code Exec via Cmd Validation in JetBrains Junie <252.284.66In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 code execution was possible due to improper command validation |
|
| CVE-2025-59457 | Sep 17, 2025 |
TeamCity < 2025.07.2 Git URL Validation Flaw Causing Credential Leak on WindowsIn JetBrains TeamCity before 2025.07.2 missing Git URL validation allowed credential leakage on Windows |
|
| CVE-2025-59456 | Sep 17, 2025 |
JetBrains TeamCity <2025.07.2 PT on Project Archive UploadIn JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload |
|
| CVE-2025-59455 | Sep 17, 2025 |
JetBrains TeamCity Project Isolation Bypass (Race Cond.)In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition |
|
| CVE-2025-57727 | Aug 20, 2025 |
JetBrains IntelliJ IDEA pre-2025.2: Remote Credentials DisclosureIn JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference |
|
| CVE-2025-57728 | Aug 20, 2025 |
IntelliJ IDEA <2025.2: Code With Me Guest Hidden File DisclosureIn JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files |
|
| CVE-2025-57729 | Aug 20, 2025 |
JetBrains IntelliJ IDEA <=2025.1 LSP Auto-Start Enables Unexpected Plugin LaunchIn JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start |
|
| CVE-2025-57730 | Aug 20, 2025 |
CVE-2025-57730: HTML Injection via Remote Dev in IntelliJ IDEA < 2025.2In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature |
|
| CVE-2025-57731 | Aug 20, 2025 |
YouTrack XSS via Mermaid diagram pre-2025.2.92387In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content |
|
| CVE-2025-57732 | Aug 20, 2025 |
JetBrains TeamCity <2025.07.1> Privilege Escalation via Wrong Dir OwnershipIn JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership |
|
| CVE-2025-57733 | Aug 20, 2025 |
TeamCity <2025.07.1 – SMTP Injection via email componentIn JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content |
|
| CVE-2025-57734 | Aug 20, 2025 |
TeamCity <2025.07.1: AWS Creds Leak in Docker ScriptsIn JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files |
|
| CVE-2025-54528 | Jul 28, 2025 |
JetBrains TeamCity CSRF in GitHub App flow (before 2025.07)In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow |
|
| CVE-2025-54538 | Jul 28, 2025 |
TeamCity before 2025.07: Password Exposure via hg pull command lineIn JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command |
|
| CVE-2025-54537 | Jul 28, 2025 |
TeamCity <=2025.07: Credentials stored in plain text in memory snapshotsIn JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots |
|
| CVE-2025-54535 | Jul 28, 2025 |
JetBrains TeamCity <2025.07 Weak Hashing of Reset/Verify TokensIn JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms |
|
| CVE-2025-54534 | Jul 28, 2025 |
TeamCity <=2025.07 Reflected XSS on agentpushPresetIn JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page |
|
| CVE-2025-54533 | Jul 28, 2025 |
TeamCity before 2025.07: Improper Access Control Exposes VCS Build SettingsIn JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration |
|
| CVE-2025-54532 | Jul 28, 2025 |
TeamCity <=2025.07 Improper Access Control - Disclosure of Build SettingsIn JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies |
|
| CVE-2025-54536 | Jul 28, 2025 |
JetBrains TeamCity <2025.07 CSRF on GraphQL EndpointIn JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint |
|
| CVE-2025-54531 | Jul 28, 2025 |
TeamCity 2025.07 Path Traversal via Plugin Unpacking on WindowsIn JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows |
|
| CVE-2025-54530 | Jul 28, 2025 |
JetBrains TeamCity <=2025.06 Priv Escalation via Incorrect Directory PermissionsIn JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions |
|
| CVE-2025-54529 | Jul 28, 2025 |
JetBrains TeamCity < 2025.07 CSRF via External OAuthIn JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration |
|
| CVE-2025-54527 | Jul 28, 2025 |
YouTrack XSS via iframe sandbox bypass before 2025.2.86935In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions |
|
| CVE-2025-53959 | Jul 15, 2025 |
YouTrack < 2025.2.86069 Email Spoofing via Admin APIIn JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible |
|