CVE-2026-49384: XSS
Published May 29, 2026
·Updated
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
Affected Software
2 affected components
JetBrains PyCharm<2025.3.4
JetBrains PyCharm<2025.3.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains PyCharmto a version that resolves this vulnerability.Fixed in 2025.3.4
Event History
May 29, 2026
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-49384?
CVE-2026-49384 has a severity score of 6.1, classified as medium.
2
What vulnerability does CVE-2026-49384 describe?
CVE-2026-49384 describes a stored XSS vulnerability in Jupyter notebook Markdown cells within JetBrains PyCharm.
3
How do I fix CVE-2026-49384?
To fix CVE-2026-49384, update to JetBrains PyCharm version 2025.3.4 or later.
4
What software is affected by CVE-2026-49384?
CVE-2026-49384 affects JetBrains PyCharm prior to version 2025.3.4.
5
What attack vectors are associated with CVE-2026-49384?
CVE-2026-49384 can be exploited through user interaction with infected Jupyter notebook Markdown cells.