Inclusion of Functionality from Untrusted Control Sphere in IntelliJ IDEA - CVE-2026-64811
Published: August 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to inclusion of functionality from untrusted control sphere in development container configuration when processing a project before trust is granted. A remote attacker can supply a specially crafted development container configuration to execute arbitrary code.
User interaction is required to open a project containing the crafted configuration.