In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
This is an XML External Entity (XXE) vulnerability affecting JetBrains IntelliJ IDEA's UI Designer form parser. A local attacker could craft a malicious XML file that, when parsed, might lead to information disclosure or server-side request forgery.
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
Users of JetBrains IntelliJ IDEA before version 2026.1 are at low risk of information disclosure or SSRF if they process malicious UI Designer forms locally.
Monitor & Review
Low severity — keep this CVE on your radar and patch during routine maintenance.
What should I do?
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
0
Affected Products
1
References
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability
Impact