CVE-2025-57729: High severity JetBrains IntelliJ IDEA vulnerability
Published Aug 20, 2025
·Updated
In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start
Affected Software
2 affected components
JetBrains IntelliJ IDEA<2025.2
JetBrains IntelliJ IDEA<2025.2
Event History
Aug 20, 2025
CVE Published
via MITRE·09:13 AM
Data Sourced
via MITRE·09:13 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-57729?
CVE-2025-57729 has been classified as a moderate severity vulnerability due to its potential impact on security through unintended plugin execution.
2
How do I fix CVE-2025-57729?
To fix CVE-2025-57729, upgrade JetBrains IntelliJ IDEA to version 2025.2 or later, which includes security enhancements.
3
What is the exploit vector for CVE-2025-57729?
The exploit vector for CVE-2025-57729 involves the automatic startup of plugins through an unintended initialization of the LSP server.
4
Is CVE-2025-57729 a local or remote vulnerability?
CVE-2025-57729 is considered a local vulnerability, as it requires access to the IntelliJ IDEA environment to exploit.
5
What versions of IntelliJ IDEA are affected by CVE-2025-57729?
CVE-2025-57729 affects all versions of JetBrains IntelliJ IDEA prior to 2025.2.