Improper Access Control in JetBrains IntelliJ IDEA - JetBrains
CVE-2025-57728

6.5MEDIUM

Key Information:

Vendor

Jetbrains

Vendor
CVE Published:
20 August 2025

What is CVE-2025-57728?

In JetBrains IntelliJ IDEA versions prior to 2025.2, an improper access control vulnerability was discovered that enabled guests in Code With Me to access hidden files within the IDE. This security gap raises concerns about the potential exposure of sensitive data, and it is critical for users to update their software to the latest version to mitigate these risks. More details can be found on JetBrains' official privacy and security page.

Affected Version(s)

IntelliJ IDEA 0 < 2025.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-57728 : Improper Access Control in JetBrains IntelliJ IDEA - JetBrains