2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-in web server
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ |
|
Tue, 05 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jetbrains:intellij_idea:2024.3.7.1:*:*:*:*:*:*:* cpe:2.3:a:jetbrains:intellij_idea:2025.1.7.1:*:*:*:*:*:*:* cpe:2.3:a:jetbrains:intellij_idea:2025.2.6.2:*:*:*:*:*:*:* cpe:2.3:a:jetbrains:intellij_idea:2025.3.4.1:*:*:*:*:*:*:* cpe:2.3:a:jetbrains:intellij_idea:2026.1.1:*:*:*:*:*:*:* |
Sat, 02 May 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Local File Access via Built‑in Web Server in IntelliJ IDEA |
Thu, 30 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jetbrains
Jetbrains intellij Idea |
|
| Vendors & Products |
Jetbrains
Jetbrains intellij Idea |
|
| Metrics |
ssvc
|
Thu, 30 Apr 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: JetBrains
Published:
Updated: 2026-04-30T13:05:06.370Z
Reserved: 2026-04-22T15:04:29.230Z
Link: CVE-2026-41882
Updated: 2026-04-30T13:05:03.370Z
Status : Analyzed
Published: 2026-04-30T12:16:24.207
Modified: 2026-05-05T00:24:51.107
Link: CVE-2026-41882
No data.
OpenCVE Enrichment
Updated: 2026-05-02T00:30:16Z