CVE-2026-59792

intellij_idea: Relative Path Traversal (CVE-2026-59792)

criticalEPSS 0.6%

Affected

  • jetbrains/intellij_idea lt *..2026.1.4

Description

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

jetbrainsintellij_idea
2026.1.4fixed from 2026.1.4

Metrics

9.6
Source: nvd-v3
47.4 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.6 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-10 15:16 UTC
CWE-23

Weakness classes (CWE)

  • CWE-23Base

    Relative Path Traversal

    The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

    cwe.mitre.org →

References & sources

Linked advisories