Vulnerability  ·  2026-10-01

JetBrains Rider AI Assistant auto-updates third-party skills without user confirmation

VulnerabilityLow impactGlobalCVE-2026-100265
NVD published 2026-09-30 noting Rider's AI Assistant could auto-update third-party skills without user confirmation; fixed in 2026.2.1.
Auto-updating agent 'skills' without confirmation is a silent supply-chain vector into a developer's IDE AI assistant — code-generation behaviour can be altered to subtly introduce malicious outputs or exfiltrate context.
Third-party AI skills are auto-updated without confirmation, so a skill provider (or a compromised/typosquatted skill source) can change what the coding assistant executes/relies on without the user noticing.
JetBrains Rider before 2026.2.1 (AI Assistant)
Update JetBrains Rider to 2026.2.1 or later.
JetBrains issues-fixed pageNVD
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →