
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-100265 is a vulnerability in JetBrains Rider's AI Assistant component that allows third-party skills to be auto-updated without user confirmation. All versions of JetBrains Rider before 2026.2.1 are affected. The vulnerability was published on September 30, 2026, and is classified as CWE-494 (Download of Code Without Integrity Check). It carries a CVSS v3.1 base score of 4.8 (Medium), though Feedly's category estimate flags it as HIGH severity (JetBrains).
The root cause is classified as CWE-494 (Download of Code Without Integrity Check), meaning the AI Assistant feature in JetBrains Rider can silently download and apply updates to third-party skills without verifying their integrity or obtaining explicit user consent. The attack vector is network-based with high attack complexity and requires no privileges or user interaction, suggesting an adversary-in-the-middle or supply chain scenario where a malicious update could be injected. This maps to CAPEC patterns including Malicious Software Update (CAPEC-186), Malicious Automated Software Update via Redirection (CAPEC-187), and Malicious Automated Software Update via Spoofing (CAPEC-657) (JetBrains).
Successful exploitation could result in limited confidentiality and integrity impacts — an attacker who can intercept or spoof the update channel for AI Assistant third-party skills could cause Rider to silently install malicious skill code on a developer's workstation. This could expose sensitive project data or source code accessible within the IDE environment, or introduce malicious behavior into the development workflow. Availability is not impacted, and the scope is unchanged, limiting the blast radius to the affected Rider instance (JetBrains).
As of the publication date, there are no known public proof-of-concept exploits, no reported in-the-wild exploitation, and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The NVD SSVC assessment confirms exploitation status as "none" and notes the vulnerability is not automatable (JetBrains).
JetBrains has released JetBrains Rider 2026.2.1, which addresses this vulnerability by requiring user confirmation before auto-updating third-party AI Assistant skills. Users should upgrade to version 2026.2.1 or later as the primary remediation. As a temporary workaround, users can disable the AI Assistant feature or avoid configuring third-party skills until the patch is applied. Organizations should also ensure developer workstations use trusted network paths and consider monitoring for unexpected skill update activity (JetBrains).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."