In June 2024, JetBrains fixed a critical vulnerability, CVE-2024-37051, in the GitHub plugin used by its IntelliJ-based IDEs, including IntelliJ IDEA, PyCharm, GoLand, WebStorm and Rider. According to JetBrains, "malicious content as part of a pull request to a GitHub project which would be handled by IntelliJ-based IDEs, would expose access tokens to a third-party host." In other words, a developer who opened a crafted pull request in their IDE could have their GitHub token sent to an attacker. The flaw affected every IntelliJ-based IDE from version 2023.1 with the GitHub plugin enabled and in use. JetBrains received the report on 29 May 2024, released fixed versions, removed vulnerable plugin versions from its marketplace and worked with GitHub on mitigation. It told users who had used the IDE's pull request features to revoke the plugin's GitHub tokens, whether OAuth or personal access tokens. JetBrains said there was no confirmed evidence of exploitation.
Key takeaways
- CVE-2024-37051 let malicious pull request content make IntelliJ-based IDEs send GitHub access tokens to a third-party host.
- All IntelliJ-based IDEs from 2023.1 with the GitHub plugin in use were affected, including Android Studio.
- JetBrains released fixes, pulled vulnerable plugin versions and worked with GitHub on mitigation.
- Users who had used pull request features were told to revoke the plugin's OAuth and personal access tokens.
- The identity lesson: developer tools hold powerful tokens, and a stolen token bypasses MFA on the account it belongs to.
At a glance
| Organisations | JetBrains (IntelliJ-based IDEs and GitHub plugin); users of the plugin |
|---|---|
| When | Reported 29 May 2024; disclosed and fixed June 2024 |
| Attacker | None known. Reported by an external researcher |
| Entry point | Malicious content in a GitHub pull request handled by the IDE |
| Identities abused | GitHub OAuth tokens and personal access tokens used by the JetBrains GitHub plugin; none confirmed abused |
| Impact | Potential disclosure of developers' GitHub tokens; no confirmed exploitation |
| Category | NHI. Incident class: vulnerability in a developer tool (vulnerability, no confirmed breach) |
What happened
JetBrains' advisory explained: "On the 29th of May 2024 we received an external security report with details of a possible vulnerability that would affect pull requests within the IDE." The issue "could lead to disclosure of access tokens to third-party sites" and affected "all IntelliJ-based IDEs as of 2023.1 onwards that have the JetBrains GitHub plugin enabled and configured/in-use." JetBrains said it "immediately contacted GitHub to assist us with mitigation," and warned that as a result the plugin in older IDE versions might no longer work as expected.
The fix came in new versions of each IDE, and "previously affected versions have been removed from JetBrains Marketplace." JetBrains also asked users to clean up: "if you have actively used GitHub pull request functionality in the IDE, we strongly advise that you revoke any GitHub tokens being used by the plugin." Because the plugin could use either OAuth or a personal access token, users had to revoke the JetBrains IDE Integration OAuth app and delete the plugin's token, which by default was named "IntelliJ IDEA GitHub integration plugin." Help Net Security noted that Android Studio users also needed to update.
A JetBrains representative told Help Net Security: "There is no confirmed evidence that attackers actively exploited [the vulnerability] before its discovery and disclosure." They also explained why the tokens mattered: "if an attacker obtains a valid token, they can use it to access the associated GitHub account's resources, regardless of whether MFA is enabled on the account."
Timeline
| Date | Event |
|---|---|
| 29 May 2024 | JetBrains receives an external security report. |
| June 2024 | JetBrains publishes fixed IDE versions and its advisory, and removes vulnerable plugin versions. |
| 11 June 2024 | BleepingComputer and Help Net Security report CVE-2024-37051. |
How it happened: the identity attack path
- Token in the IDE. The GitHub plugin held an OAuth or personal access token for the developer's account.
- Malicious pull request. An attacker could place crafted content in a pull request to a GitHub project.
- IDE processes it. When the IDE handled the pull request, the flaw caused the token to be sent to a third-party host.
- Account access. A stolen token would give access to the developer's GitHub resources, bypassing MFA.
- Fixed and revoked. JetBrains patched the IDEs and told users to revoke tokens.
Impact
- Potential: theft of GitHub tokens from developers using pull request features in affected IDEs.
- Actual: no confirmed exploitation, according to JetBrains.
- Response: fixed IDE versions, vulnerable plugins removed and token revocation advised.
What this means for NHI governance
Developer tools are credential stores. An IDE plugin that talks to GitHub holds a token with the developer's access to code, and often much more. When that tool processes untrusted content, such as a pull request from an outsider, the token is only as safe as the parser. As JetBrains pointed out, MFA does not help once a token is taken.
The controls are short-lived, narrowly scoped tokens for tools, a record of which tools hold which tokens, and the ability to revoke them fast. See our Token and Session Security Guide and AI Coding Agents Security Guide.
Recommendations
- Patch developer tools quickly. Treat IDE and plugin updates as security updates. See our AI Coding Agents Security Guide.
- Revoke tokens after a tool flaw. Rotate every token the affected tool held. See the Leaked Credential Response Playbook.
- Use fine-grained, expiring tokens. Limit each tool's token to the repositories it needs. See the Token and Session Security Guide.
- Review authorised OAuth apps. Remove integrations that are no longer used. See the SaaS and OAuth App Governance Guide.
- Monitor GitHub audit logs. Watch for token use from unexpected locations. See the ITDR Guide.
Frequently asked questions
What is CVE-2024-37051?
A vulnerability in the JetBrains GitHub plugin for IntelliJ-based IDEs where malicious pull request content could cause the IDE to send GitHub access tokens to a third-party host.
Was JetBrains breached?
No. The flaw was reported by an external researcher and fixed. JetBrains said there was no confirmed evidence of exploitation.
What should affected developers do?
Update the IDE and, if they used pull request features, revoke the JetBrains IDE Integration OAuth app and delete the plugin's personal access token.
Related NHI Mgmt Group resources
Secrets in VS Code Extensions 2025 · GlassWorm Campaign 2025 · Token and Session Security Guide · AI Coding Agents Security Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Every developer tool that touches code holds a token. We help teams inventory those tokens, scope them and revoke them fast when a tool is found vulnerable. See our NHI and AI agent security training.
References
- JetBrains: Updates for security issue affecting IntelliJ-based IDEs 2023.1+ and JetBrains GitHub Plugin (June 2024)
- BleepingComputer: JetBrains warns of IntelliJ IDE bug exposing GitHub access tokens (11 June 2024)
- Help Net Security: Users of JetBrains IDEs at risk of GitHub access token compromise (CVE-2024-37051) (11 June 2024)