Command injection in IntelliJ IDEA - CVE-2026-75052
Published: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to command injection in the Markdown preview component when rendering crafted Markdown content in a trusted project. A remote user can create crafted Markdown preview content to execute arbitrary commands.
Exploitation is possible only in trusted projects.