| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible |
| In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions |
| In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows |
| In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start |
| In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership |
| In JetBrains IDE Services before 2025.5.0.1086,
2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves |
| In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure |
| In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation |
| In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition |
| In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint |
| In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible |
| In JetBrains Hub before 2025.3.119807 authentication bypass allowing administrative actions was possible |
| In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow |
| In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations |
| In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk |
| In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions. |
| In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs |
| In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible |
| In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit |
| In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API |