Inclusion of Functionality from Untrusted Control Sphere in IntelliJ IDEA - CVE-2026-86504
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute code on the host system.
The vulnerability exists due to improper control of functionality from an untrusted control sphere in the Dev Container build process when building a Dev Container from an untrusted project. A remote attacker can build a Dev Container from an untrusted project to execute code on the host system.