← Vulnerability feed

Vulnerability record · CVE-2021-30005 · published 11 May 2021

CVE-2021-30005: Jetbrains pycharm insufficient verification of data authenticity vulnerability

Jetbrains · Pycharm

In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

7.8 CVSS 3.1 High EPSS 0.88% · top 42.5% CWE-345 · Insufficient verification of data authenticity
7.8CVSS 3.1 base score, v2 4.6
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-30005 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-45977Jetbrains clion vulnerabilityJetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, Ph…EPSS 1.1%8.6CVE-2026-65908Jetbrains pycharm inclusion from untrusted sphere vulnerabilityIn JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project openEPSS 0.19%8.4CVE-2026-75060Jetbrains pycharm missing authentication for critical function vulnerabilityIn JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP toolsEPSS 0.18%7.7CVE-2022-29821Jetbrains pycharm code injection vulnerabilityIn JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possibleEPSS 0.23%7.5CVE-2024-37051Jetbrains aqua insufficiently protected credentials vulnerabilityGitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 202…EPSS 3.8%7.5CVE-2020-11694Jetbrains pycharm cleartext storage of sensitive data vulnerabilityIn JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.EPSS 1.9%7.5CVE-2019-14958Jetbrains pycharm allocation without limits vulnerabilityJetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could l…EPSS 1.9%6.1CVE-2026-49384Jetbrains pycharm cross-site scripting vulnerabilityIn JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possibleEPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2021-30005), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.