Stored XSS Vulnerability in JetBrains PyCharm Jupyter Notebook
CVE-2026-49384
6.1MEDIUM
What is CVE-2026-49384?
A vulnerability exists in JetBrains PyCharm prior to version 2025.3.4, allowing stored Cross-Site Scripting (XSS) attacks through Jupyter notebook Markdown cells. This flaw can enable an attacker to inject malicious scripts, which may execute whenever a user accesses a compromised notebook, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
PyCharm 0 < 2025.3.4