Please do not report security vulnerabilities through public issues or discussions.
Instead, report them privately through GitHub Security Advisories.
Please include:
- the affected plugin and its version;
- the IDE version and operating system;
- steps to reproduce or a proof of concept;
- the impact you expect.
You will get an initial response within 7 days. Once the issue is fixed, the advisory is published together with the release that contains the fix.
Only the latest published version of each plugin on the JetBrains Marketplace receives security fixes.