CVE-2026-25847: XSS
Published Feb 9, 2026
·Updated
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
Affected Software
2 affected components
JetBrains PyCharm<2025.3.2
JetBrains PyCharm<2025.3.2
Event History
Feb 9, 2026
CVE Published
via MITRE·10:39 AM
Data Sourced
via MITRE·10:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Nov 23, 58106
Event
via FIRST·07:25 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-25847?
CVE-2026-25847 is classified as a high-severity vulnerability due to the potential for DOM-based XSS attacks.
2
How do I fix CVE-2026-25847?
To fix CVE-2026-25847, users should upgrade to JetBrains PyCharm version 2025.3.2 or later.
3
What does CVE-2026-25847 affect?
CVE-2026-25847 affects JetBrains PyCharm versions prior to 2025.3.2 that include the Jupyter viewer page.
4
What type of vulnerability is CVE-2026-25847?
CVE-2026-25847 is a DOM-based Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2026-25847 compromise user data?
Yes, CVE-2026-25847 can be exploited to execute malicious scripts in the context of the user’s session, potentially compromising sensitive data.