VendorsJetBrainspycharmany version
Vulnerabilities

JetBrains PyCharm any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-37051
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7, 2024.1.3, 2024.2 EAP3; PyCharm 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.3, 2024.2 EAP2; Rider 2023.1.7, 2023.2.5, 2023.3.6, 2024.1.3; RubyMine 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP4; RustRover 2024.1.1; WebStorm 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.4
Published 2024-06-10 · Modified
9.3EPSS 0.038
CVE-2026-65908
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
Published 2026-07-23 · Analyzed
8.6EPSS 0.002
CVE-2026-75060
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
Published 2026-08-17 · Analyzed
8.4EPSS 0.002
CVE-2026-25847
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
Published 2026-02-09 · Analyzed
8.2EPSS 0.003
CVE-2021-30005
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
Published 2021-05-11 · Modified
7.8EPSS 0.009
CVE-2022-29821
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
Published 2022-04-28 · Modified
7.7EPSS 0.002
CVE-2019-14958
JetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could lead to a remote invocation of an OOM error message because of Uncontrolled Memory Allocation.
Published 2019-10-02 · Modified
7.5EPSS 0.019
CVE-2026-49384
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
Published 2026-05-29 · Analyzed
6.1EPSS 0.003
CVE-2026-75059
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
Published 2026-08-17 · Analyzed
4.4EPSS 0.002
CVE-2022-29820
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
Published 2022-04-28 · Modified
3.5EPSS 0.004