Inclusion of Functionality from Untrusted Control Sphere in IntelliJ IDEA - CVE-2026-100256
Published: October 2, 2026 / Updated: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to inclusion of functionality from an untrusted control sphere in Structural Search script constraints when opening an untrusted project. A remote attacker can supply an untrusted project containing Structural Search script constraints to execute arbitrary code.