CyberRota Analysis
AI-GeneratedJetBrains IntelliJ IDEA versions prior to 2026.2 are vulnerable to HTML injection in IDE notifications, which could enable attackers to silently track user activities. This vulnerability poses a medium risk, particularly for organizations that rely on IntelliJ IDEA for software development and need to safeguard user privacy and data integrity. Users and administrators of affected versions should prioritize applying updates to mitigate potential exploitation.
CVE
CVE-2026-64810
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%
Original NVD Description
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
Related CVEs
Other vulnerabilities affecting the same vendor(s)