CVE-2026-49384
Published May 29, 2026In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
9 CVEs tagged to jetbrains / pycharm — 2 Critical, 4 High, 2 Medium, 1 Low, 0 Unrated.
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3;…
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2…
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of…