CyberRota Analysis
AI-GeneratedJetBrains IntelliJ IDEA versions prior to 2026.2.2 are vulnerable due to a lack of project-trust confirmation before building a Dev Container, which could allow an attacker to execute arbitrary code at the host level. This high-severity vulnerability poses significant risks for developers and organizations using IntelliJ IDEA, particularly those that work with untrusted code or third-party projects. Users of affected versions should prioritize applying the latest updates to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution