Untriaged
Permalink
CVE-2026-25847
8.2 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): LOW
Activity log
- Created suggestion
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter …
In JetBrains PyCharm before 2025.3.2 a DOM-based XSS on Jupyter viewer page was possible
Affected products
PyCharm
- <2025.3.2
Matching in nixpkgs
pkgs.jetbrains.pycharm
Python IDE from JetBrains
pkgs.jetbrains.pycharm-oss
Free Python IDE from JetBrains (built from source)
-
nixos-unstable -
- nixpkgs-unstable 2025.3.1.1
- nixos-unstable-small 2025.3.1.1
-
nixos-25.11 2025.1.1.1
- nixpkgs-25.11-darwin 2025.1.1.1
pkgs.jetbrains.pycharm-professional
Paid-for Python IDE from JetBrains
-
nixos-unstable 2025.2
pkgs.jetbrains.pycharm-community-bin
Free Python IDE from JetBrains (patched binaries from jetbrains)
-
nixos-unstable 2025.2
pkgs.jetbrains.pycharm-community-src
Free Python IDE from JetBrains (built from source)
-
nixos-unstable 2025.1.1.1
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
-
@edwtjo Edward Tjörnhammar <ed@cflags.cc>
-
@GenericNerdyUsername GenericNerdyUsername <genericnerdyusername@proton.me>
-
@theCapypara Marco Köpcke <hello@capypara.de>
-
@thiagokokada Thiago K. Okada <thiagokokada@gmail.com>
-
@jamesward James Ward <james@jamesward.com>
-
@tymscar Oscar Molnar <oscar@tymscar.com>