CVE-2026-59792
intellij_idea: Relative Path Traversal (CVE-2026-59792)
criticalEPSS 0.6%
Affected
- jetbrains/intellij_idea
lt *..2026.1.4
Description
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
jetbrainsintellij_idea
2026.1.4fixed from 2026.1.4Metrics
Show all metrics
Severity
critical
87.81
no public PoC known
9.6
Published
2026-07-10 15:16 UTC
CWE-23
Weakness classes (CWE)
CWE-23Base
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
cwe.mitre.org →