Critical IntelliJ IDEA Path Traversal Flaw Enables Code Execution
ID: caf09366-d000-5e0c-9d85-c6a4fd61378f
STIX ID: report--caf09366-d000-5e0c-9d85-c6a4fd61378f
Feed Name: Cyber Press
Threat Score
JetBrains released patches for a critical path traversal vulnerability in IntelliJ IDEA (CVE-2026-59792, CVSS 9.6) that allows unauthenticated arbitrary code execution by opening a specially crafted project; the advisory lists multiple additional IntelliJ IDEA and TeamCity flaws and urges upgrading to 2026.1.4/2026.2 for the IDE and 2026.1.2 for TeamCity while warning of supply-chain-style risks from malicious repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
