JetBrains IntelliJ IDEA Automatic LSP Server Start Vulnerability Allowing Unexpected Plugin Startup

Vulnerability

A vulnerability exists in JetBrains IntelliJ IDEA versions prior to 2025.2, where plugins could unexpectedly start due to the automatic initiation of the Language Server Protocol (LSP) server.

Impact

This vulnerability could lead to unauthorized or unexpected execution of plugin code, potentially causing further security issues or disruptions.

Remediation

Users can update to JetBrains IntelliJ IDEA version 2025.2 or later to address this vulnerability.

Added: Aug 20, 2025, 10:24 AM
Updated: Aug 20, 2025, 10:24 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
10.0
exploitability
3.3
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.