JetBrains Hub ships 2026.1.13757 patching two critical auth-bypass CVEs
JetBrains Hub 2026.1.13757 fixes CVE-2026-50242 (CVSS 10.0 auth bypass) and CVE-2026-56141 (CVSS 9.8 account takeover via predictable restore codes). LTS backports available.
JetBrains Hub 2026.1.13757 fixes CVE-2026-50242 (CVSS 10.0 auth bypass) and CVE-2026-56141 (CVSS 9.8 account takeover via predictable restore codes). LTS backports available.
Aikido Security found 15 JetBrains Marketplace plugins under 7 vendor accounts that exfiltrated OpenAI, DeepSeek, and SiliconFlow keys over plaintext HTTP. JetBrains pulled them on June 16, 2026.