Sceawere

Vulnerability Detail

CVE-2026-75052UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IntelliJ IDEA Markdown Command Execution

Vulnerability Metadata

Severity
Low
Score / CVSS
3.6
Creation Date
5h ago
Vendor
JetBrains
Product
IntelliJ IDEA
Attack Type
CWE-77
Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.6",
  "pubDate": "2026-08-17T16:17:52.320Z",
  "pubdate": "2026-08-17T16:17:52.320Z",
  "executiveSummary": "A command execution vulnerability has been identified in JetBrains IntelliJ IDEA affecting versions prior to 2026.2.1.\nThe vulnerability allows threat actors to achieve arbitrary command execution through the processing of maliciously crafted Markdown preview content.\nSuccessful exploitation of this security flaw impacts the confidentiality, integrity, and availability of the host system running the affected software.\nThe risk implication is severe, as an attacker with the ability to supply crafted content can leverage the integrated development environment to execute arbitrary operating system commands.\nAttacker capabilities require the manipulation of Markdown content within the context of targeted projects.\nA key exploitation requirement specified for this vulnerability is that the attack vector relies on trusted projects, meaning the execution context leverages trust assumptions within the application.\nOrganizations and developers utilizing vulnerable versions of IntelliJ IDEA face potential system compromise if they open or preview untrusted or maliciously modified Markdown files within trusted project environments.",
  "technicalDetails": "The vulnerability resides within the Markdown preview component of JetBrains IntelliJ IDEA, specifically concerning how crafted Markdown preview content is parsed, rendered, or handled.\nThe root cause stems from insufficient input sanitization, unsafe rendering practices, or improper handling of embedded instructions within the Markdown preview subsystem.\nAffected versions comprise all JetBrains IntelliJ IDEA builds released prior to 2026.2.1.\nThe attack flow begins when an attacker introduces maliciously crafted Markdown content into a project file that is subsequently processed by the IntelliJ IDEA Markdown preview engine.\nBecause the vulnerability manifests in trusted projects, the application may execute the embedded malicious payload with the privileges of the user running the IDE.\nUpon rendering the crafted Markdown content, the vulnerable component improperly interprets or delegates payload instructions, triggering unintended execution pathways.\nThis behavior leads directly to arbitrary command execution on the underlying host operating system.\nAuthentication and network exposure requirements depend on how the project files are acquired and opened, but local or repository-based vector manipulation is sufficient to stage the payload.\nPrivilege requirements are limited to the user privileges associated with the running instance of IntelliJ IDEA.\nThe post-exploitation impact includes full code execution capabilities within the security context of the user, potentially allowing further system enumeration, data exfiltration, or deployment of additional malicious artifacts."
}
CVE-2026-75052: IntelliJ IDEA Markdown Command Execution (LOW Severity, CVSS: 3.6) - Sceawere