
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75056 is a Remote Code Execution (RCE) vulnerability in JetBrains IntelliJ IDEA's Markdown export tool that allows a local, unprivileged attacker to execute arbitrary code through user interaction. It affects all versions of IntelliJ IDEA before 2026.2.1. The vulnerability was published on August 17, 2026, with a patch available in version 2026.2.1. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, JetBrains).
The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command / OS Command Injection), meaning the Markdown export tool fails to properly sanitize or neutralize user-controlled input before incorporating it into an OS-level command (GitHub Advisory). The attack vector is local, requires no special privileges, and is triggered through user interaction — specifically, when a user exports a Markdown file within the IDE. A malicious Markdown file with specially crafted content could inject OS commands that are executed by the IntelliJ IDEA process during the export operation. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (GitHub Advisory).
Successful exploitation grants an attacker code execution with the privileges of the IntelliJ IDEA process, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive files (e.g., source code, credentials, SSH keys), modify or delete files, and disrupt system operations. Because developers often run IntelliJ IDEA with elevated user-level permissions and access to sensitive repositories and credentials, exploitation could facilitate lateral movement or supply chain compromise (GitHub Advisory, JetBrains).
As of the disclosure date (August 17, 2026), there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is 0.0, and the NVD SSVC assessment indicates exploitation is currently "none" and the vulnerability is not automatable (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — specifically, a victim must open and export a maliciously crafted Markdown file — which limits the attack surface compared to fully remote, zero-interaction vulnerabilities.
.md file to a developer using a vulnerable version of IntelliJ IDEA (before 2026.2.1) via phishing email, a compromised repository, a pull request, or a shared project.cmd.exe, powershell.exe, /bin/sh, /bin/bash, curl, wget) during or after a Markdown export operation..bashrc, .zshrc, ~/.profile) or scheduled task/cron entries.JetBrains has released IntelliJ IDEA version 2026.2.1, which addresses this vulnerability. Users should update to version 2026.2.1 or later as the primary remediation (JetBrains, GitHub Advisory). As a temporary workaround prior to patching, users should avoid opening or exporting Markdown files from untrusted or unverified sources. Organizations should also consider restricting the use of the Markdown export feature via policy until the patch is applied.
The vulnerability was noted on Mastodon via The Hacker Wire shortly after disclosure on August 17, 2026, indicating early community awareness. No significant vendor statements beyond the JetBrains security advisory page, nor notable independent researcher commentary or media coverage, have been identified as of the disclosure date (JetBrains).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."