CVE-2026-100265: Medium severity JetBrains Rider vulnerability
Published Sep 30, 2026
·Updated
In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
Affected Software
1 affected component
JetBrains Rider<2026.2.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains Riderto a version that resolves this vulnerability.Fixed in 2026.2.1
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users of JetBrains Rider versions before 2026.2.1 are affected where the AI Assistant can auto-update third-party skills.
2
Does exploitation require an authenticated user or user interaction?
No privileges or user interaction are required according to the CVSS vector. The attack is network-based, but has high attack complexity.
3
What is the immediate remediation?
Update JetBrains Rider to version 2026.2.1 or later. This issue is addressed in that release.